Back to skill

Security audit

admapix

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed AdMapix analytics skill that queries AdMapix with a configured API key, with no hidden persistence or destructive behavior found.

Install only if you are comfortable sending ad intelligence searches, app names, competitor names, and related business terms to AdMapix. Use a dedicated API key, avoid entering personal identifiers or highly sensitive unreleased campaign details unless AdMapix is approved for that data, and rotate the key if it is ever exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
90% confidence
Finding
Defaulting to Creative Search whenever intent is uncertain creates an overly broad activation path for a network-enabled skill. On ambiguous user input, the agent may perform unintended external queries and disclose user-provided terms to the AdMapix API without sufficiently clear user intent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Using generic signals like "search" and "find" for Browse mode overlaps with normal conversation and increases the chance of accidental invocation. In a skill that can make authenticated outbound requests, that ambiguity can cause unintended data transmission and actions the user did not mean to trigger.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document instructs use of an API key in requests but does not warn that the secret must be kept server-side, excluded from logs, and never embedded in client-visible code. In skill and agent ecosystems, such omissions often lead to accidental credential exposure through prompts, debug output, browser code, or shared examples.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The `delivery` object includes `externalUserId` for H5 page generation but the documentation provides no privacy or minimization guidance. This can cause integrators to send stable identifiers unnecessarily, exposing personal or pseudonymous user data to a third party and increasing tracking/privacy risk.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.