Back to skill

Security audit

PipiAds - TikTok Ad Tracker & Monitor

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently connects a PipiAds MCP server to TikTok ad research and monitoring, with disclosed API-key and credit usage risks.

Before installing, verify that the npm package and the pipispy.com billing/API-key flow are legitimately associated with PipiAds, use a revocable API key, monitor credit usage, and uninstall the global package if you stop using the skill.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unreviewable Globally Installed Third-Party MCP Server

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8–20
Vulnerability Type: Third-party supply-chain exposure through global npm installation
Risk Level: Medium

Vulnerable Configuration:

yaml
bins:
  - npm
install:
  command: npm
  args:
    - install
    - -g
    - "pipiads-mcp-server@1.0.3"
primaryEnv: PIPIADS_API_KEY
emoji: "📊"
homepage: https://www.pipiads.com
mcpServers:
  pipiads:
    command: pipiads-mcp-server
    env:
      PIPIADS_API_KEY: "{{PIPIADS_API_KEY}}"

Technical Analysis

The skill globally installs and executes the external npm package pipiads-mcp-server@1.0.3. The package's source code, dependency lockfile, integrity hash, and security provenance are not included in the audited project, so its installation scripts, transitive dependencies, and runtime behavior cannot be verified from the available artifact.

Pinning the version improves reproducibility but does not authenticate the downloaded package or its transitive dependencies. npm installation can also execute package lifecycle scripts. The resulting MCP server is then supplied with PIPIADS_API_KEY, placing a sensitive API credential within reach of all code loaded by the package.

There is no evidence in the reviewed file that this package is malicious. The risk arises from executing an externally retrieved, unreviewable dependency with access to a secret and from installing it globally rather than in an isolated project environment.

Attack Path

  1. A user or agent installs the skill.
  2. The installation command downloads pipiads-mcp-server@1.0.3 and its transitive dependencies from the configured npm registry.
  3. npm executes any enabled installation lifecycle scripts with the installer user's privileges.
  4. The globally installed pipiads-mcp-server executable is invoked as an MCP server.
  5. The process receives PIPIADS_API_KEY through its environment.
  6. If the packa ...[truncated 867 chars]
Remediation
View remediation

Remediation Suggestions

  • Avoid global installation. Install the MCP server in a dedicated, non-privileged project directory or isolated container.
  • Include an auditable lockfile and verify package and dependency integrity using trusted registry metadata and cryptographic hashes.
  • Review the package source, published artifact, maintainers, lifecycle scripts, and complete transitive dependency tree before deployment.
  • Disable npm lifecycle scripts during installation where they are not required, for example by using an appropriately controlled ignore-scripts policy.
  • Execute the MCP server under a sandboxed, least-privileged account with restricted filesystem and network access.
  • Supply a narrowly scoped, revocable API key and rotate it promptly if package integrity is ever questioned.
  • Prefer a locally reviewed and vendored implementation or a signed release obtained from a verified publisher.

other

Note
Location
SKILL.md:27
Finding

Credential and Billing Setup Directed to an Unverified Separate Domain

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 27–29
Vulnerability Type: Unverified external credential and billing endpoint
Risk Level: Low

Vulnerable Documentation:

markdown
1. Visit the official website at [https://pipiads.com/](https://pipiads.com/) to view real-time dashboard data and product UI.
2. Visit [https://www.pipispy.com/](https://www.pipispy.com/) to get your API key and manage billing/recharge.
3. Set the environment variable: `PIPIADS_API_KEY`

Technical Analysis

The skill declares pipiads.com as the official service website but instructs users to obtain an API key and manage billing through the separate pipispy.com domain. The audited project contains no documentation or verifiable evidence establishing ownership, authorization, or a trust relationship between these domains.

Credential issuance and billing are sensitive workflows. Directing users to a separate domain without explaining or validating the relationship creates a phishing and account-security risk if the link is incorrect, becomes compromised, changes ownership, or is impersonated.

The available evidence does not prove that pipispy.com is hostile or unauthorized. This finding concerns the absence of an auditable trust justification for directing users to a different domain for sensitive account operations.

Attack Path

  1. A user follows the setup instructions in SKILL.md.
  2. The user leaves the declared official PipiAds domain and navigates to pipispy.com.
  3. The user may submit account information, payment details, or other sensitive data while obtaining an API key or recharging an account.
  4. If that domain or its account flow is unauthorized, compromised, or impersonated, the submitted information could be captured or misused.
  5. Any resulting API credential may subsequently be placed in PIPIADS_API_KEY, potentially allowing an untrusted service to associate or control the credentia ...[truncated 537 chars]
Remediation
View remediation

Remediation Suggestions

  • Direct users to credential and billing pages hosted under the declared official domain whenever possible.
  • If the separate domain is an authorized service, explicitly document the relationship and provide a verification link from the official domain.
  • Use exact HTTPS URLs for the intended account and billing pages rather than directing users only to a separate domain's homepage.
  • Publish ownership and support information that users can independently verify before entering credentials or payment data.
  • Add guidance telling users to verify the TLS certificate, domain spelling, and official cross-domain references before submitting sensitive information.
  • Periodically validate the external link and remove it immediately if ownership, authorization, or security status changes.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.