Back to skill

Security audit

Facebook Ad Library Tracker & Monitor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed PPSPY Facebook ad-monitoring integration, with normal credential and third-party package risks users should handle carefully.

Install only if you trust PPSPY and the npm package ppspy-mcp-server@1.0.1. Store PPSPY_API_KEY as a secret, do not commit or log it, monitor credit usage because some actions consume quota, and rotate the key if you later distrust the package or account activity.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Globally Installed Third-Party MCP Server Executes with API Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10-20
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

yaml
install:
  command: npm
  args:
    - install
    - -g
    - "ppspy-mcp-server@1.0.1"
primaryEnv: PPSPY_API_KEY
emoji: "🔍"
homepage: https://www.ppspy.com
mcpServers:
  ppspy:
    command: ppspy-mcp-server
    env:
      PPSPY_API_KEY: "{{PPSPY_API_KEY}}"

Technical Analysis

The skill installs ppspy-mcp-server@1.0.1 from the npm registry using the global -g option and subsequently executes the installed command with PPSPY_API_KEY in its environment.

Pinning the direct package version reduces version drift, but the project does not provide a lockfile, integrity hash, vendored source, verified publisher information, or other mechanism through which the package and its transitive dependencies can be audited from this repository. npm lifecycle scripts may also execute during installation. The global installation scope gives package installation behavior access to user-level global npm locations beyond a project-local directory.

The inspected repository contains only SKILL.md; therefore, this finding does not establish that the referenced package is malicious. It identifies a supply-chain trust boundary in which externally retrieved and unaudited code is installed and executed with access to a credential.

Attack Path

  1. A user installs or enables the skill.
  2. The installation process retrieves ppspy-mcp-server@1.0.1 and its transitive dependencies from npm.
  3. npm executes any permitted package lifecycle scripts and places package files in the global npm installation location.
  4. The framework launches the globally installed ppspy-mcp-server executable.
  5. The process receives PPSPY_API_KEY through its environment.
  6. If the package, publisher account, registry response, or a transitive dependency has been compromised, attack ...[truncated 695 chars]
Remediation
View remediation

Remediation Suggestions

  1. Install the server in an isolated, project-local environment rather than using npm install -g.
  2. Vendor or independently audit the exact package source and all transitive dependencies before deployment.
  3. Use a lockfile and verify registry integrity hashes or package signatures against trusted, reviewed values.
  4. Disable npm lifecycle scripts during installation where operationally possible, or explicitly review every required script before allowing execution.
  5. Run the MCP server in a sandbox with restricted filesystem access, outbound network access, and operating-system privileges.
  6. Supply a narrowly scoped, revocable PPSPY API key with minimal quota and billing permissions; rotate it if package compromise is suspected.
  7. Monitor package provenance and publisher ownership, and establish a controlled update process rather than retrieving dependencies directly in production.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: facebook-ad-tracker-monitor
description: Monitor Facebook ads and advertisers with PPSPY. Create tracking tasks, analyze ad activity over time, inspect landing pages and products, and manage ad monitoring groups.
version: 1.0.0
metadata:
  openclaw:
    requires:
      env:
        - PPSPY_API_KEY
      bins:
        - npm
    install:
      command: npm
      args:
        - install
        - -g
        - "ppspy-mcp-server@1.0.1"
    primaryEnv: PPSPY_API_KEY
    emoji: "🔍"
    homepage: https://www.ppspy.com
    mcpServers:
      ppspy:
        command: ppspy-mcp-server
        env:
          PPSPY_API_KEY: "{{PPSPY_API_KEY}}"
---

# Facebook Ad Tracker & Monitor

Track

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
## Setup

1. Visit the official website at [ppspy.com](https://www.ppspy.com/) to view real-time dashboard data and product UI.
2. Visit the direct API site at [api.ppspy.com](https://api.ppspy.com/) to get your API key and manage billing/recharge.
3. Set the environment variable: `PPSPY_API_KEY`

## Available Tools (24 total)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The markdown instructs users to obtain and set PPSPY_API_KEY, which is a credential, but does not include any caution about keeping it secret, avoiding commits, or limiting sharing. For a skill that depends on a sensitive environment variable, some user-facing warning about credential handling is expected.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.