T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Globally Installed Third-Party MCP Server Executes with API Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward PPSPY/Meta ad library integration; its main risk is trusting a third-party npm MCP server with your PPSPY API key and account credits.
Install only if you trust PPSPY and the npm package ppspy-mcp-server@1.0.1. Use a revocable PPSPY API key, monitor credit/billing usage, and prefer running the MCP server in a contained environment if you want to limit the impact of a compromised dependency.
SKILL.md:12Globally Installed Third-Party MCP Server Executes with API Credentials
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
---
name: facebook-ad-library
description: Search Facebook Ad Library and Meta Ad Library data with PPSPY. Analyze ads, advertiser stores, landing pages, and ad products from one focused skill.
version: 1.0.0
metadata:
openclaw:
requires:
env:
- PPSPY_API_KEY
bins:
- npm
install:
command: npm
args:
- install
- -g
- "ppspy-mcp-server@1.0.1"
primaryEnv: PPSPY_API_KEY
emoji: "🔍"
homepage: https://www.ppspy.com
mcpServers:
ppspy:
command: ppspy-mcp-server
env:
PPSPY_API_KEY: "{{PPSPY_API_KEY}}"
---
# Facebook Ad Library
Search Facebook Ad Library and Meta Ad Library data
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Setup
1. Visit the official website at [ppspy.com](https://www.ppspy.com/) to view real-time dashboard data and product UI.
2. Visit the direct API site at [api.ppspy.com](https://api.ppspy.com/) to get your API key and manage billing/recharge.
3. Set the environment variable: `PPSPY_API_KEY`
## Available Tools (13 total)
No suspicious patterns detected.