Back to skill

Security audit

Meta Video Ad Deconstructor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Gemini-based video ad analysis helper, with some privacy and reliability caveats but no hidden persistence, privilege escalation, destructive behavior, or deceptive data flow found.

Install only in an isolated Python environment with pinned dependencies, use a least-privileged Google service account, and avoid sending confidential or unreleased creatives unless your Gemini/Vertex AI data handling terms allow it. Treat generated JSON and text as untrusted analysis output, especially for competitor ads that may contain prompt-injection text.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/deconstructor.py:119
Finding

Untrusted Video Content Is Directly Embedded into Model Instructions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:31
Finding

Third-Party Dependency Is Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code broadly matches the stated purpose of deconstructing video ads into marketing dimensions using Gemini AI. However, the declared description specifically promises extraction of hooks, social proof, CTAs, target audience, emotional triggers, and urgency tactics, while the actual DIMENSIONS list does not include explicit social_proof or call_to_action analysis. Although CTA may appear in the generated summary and social proof might be indirectly covered by 'credibility', those capabilities are not actually implemented as first-class deconstruction dimensions in this code path. Conversely, the code prominently analyzes several other dimensions not mentioned in the description, such as problem, aspiration/transformation, narrative flow, and visual format. This is a moderate description-behavior mismatch rather than a severe one, because the primary purpose still aligns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a marketing-analysis skill that deconstructs ad creatives into persuasive dimensions using Gemini AI. However, the supplied code chunk only contains a simple data model for holding extracted video content. It supports a lower-level video extraction pipeline but does not itself perform ad analysis, AI inference, or marketing attribute extraction. This is a materially different primary purpose from the declared behavior, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill analyzes video ad creatives with Gemini AI and extracts multiple advertising/marketing attributes. However, the supplied code chunk contains only infrastructure for loading and formatting prompt templates from markdown files. It does not process videos, call Gemini or any AI service, extract ad features, or perform competitor ad analysis. While prompt management could be a supporting component in a larger system, this code chunk’s actual behavior is materially different from the declared primary purpose, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description is broad enough that an orchestrator could invoke this skill for generic ad-analysis requests without clear user intent boundaries. Over-broad triggering can route sensitive or irrelevant media/transcripts to an external AI service unexpectedly, creating privacy, cost, and workflow-integrity risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The example trigger phrase 'Deconstruct this competitor's ad' is open-ended and may encourage invocation on any ad-related request without confirming scope, consent, or content handling expectations. In agent environments, vague triggers increase the chance of unintended data processing or automatic external model use on user-provided media.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code sends transcript, scene, and text-overlay data to an external Gemini service via generate_content without any visible consent, warning, or data-classification check. Even if the content is 'just ads,' extracted media may still contain sensitive or proprietary information, and transmitting it to a third party can violate privacy, contractual, or compliance expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The deconstruction loop repeatedly sends the extracted ad content and derived summary to Gemini for each marketing dimension, multiplying data exposure to an external provider. This increases privacy and data-governance risk because the same content is transmitted many times, broadening opportunities for retention, leakage, or policy noncompliance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.