Back to skill

Security audit

AdKit: Google Ads MCP & Meta Ads MCP, Facebook, Instagram, PPC Campaign Agent

Security checks for vulnerabilities and agentic risk

Overview

AdKit is a disclosed ads-management skill, but it can affect paid advertising accounts and includes broad triggers plus raw API paths that need careful review before use.

Install only if you intentionally want an agent to operate connected Google Ads or Meta Ads accounts. Prefer draft workflows, require explicit confirmation before any publish or raw API mutation, use the least-privileged ad accounts and API key, avoid global unpinned installs where possible, and be cautious with ordinary ad-research prompts that may invoke this skill.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
cli.md:5
Finding

Unpinned Global Installation of a Third-Party CLI Package

Content
View full analysis

Vulnerability Details

File Location: cli.md:5
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

Complete Code Snippet:

markdown
2. If `adkit` is not found, install it: `npm i -g @adkit/cli`.

Technical Analysis

The setup instructions install @adkit/cli globally without specifying an exact version or integrity constraint. Consequently, npm resolves whichever release the configured registry currently associates with the requested package and tag. The project contains no lockfile, checksum, signature-verification procedure, or vendored implementation that would allow the installed executable to be matched to an audited version.

A global npm installation may run package lifecycle scripts and makes the resulting executable available across the user's environment. This increases the consequences of a compromised package publisher, npm account, registry response, or release pipeline. This finding does not establish that @adkit/cli is malicious; it identifies an avoidable supply-chain exposure caused by mutable dependency resolution.

Attack Path

  1. An attacker compromises the package publisher, release pipeline, or relevant package-registry delivery path.
  2. The attacker publishes a malicious or backdoored version under the legitimate @adkit/cli package name or alters the version resolved by its default distribution tag.
  3. A user follows the documented setup command:
    bash
    npm i -g @adkit/cli
    
  4. npm retrieves the mutable current release rather than a previously reviewed, exact version.
  5. Malicious package lifecycle scripts can execute during installation, or malicious CLI logic can execute when the installed command is invoked.
  6. The payload operates with the privileges of the user running npm and may access that user's files, network connectivity, and environment variables.

Impact Assessment

Successful exploitation ...[truncated 849 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an audited exact version rather than relying on the mutable latest release:

    bash
    npm install --global --ignore-scripts @adkit/cli@0.2.3
    

    The example version must be replaced with the specific release independently reviewed and approved by the maintainer.

  2. Prefer a project-local dependency recorded in package.json and a committed lockfile. Use npm ci so installation fails if dependency resolution differs from the reviewed lockfile.

  3. Verify package provenance and integrity through npm provenance attestations, trusted publisher information, and expected integrity hashes where supported.

  4. Disable lifecycle scripts with --ignore-scripts when the package does not require them. If scripts are required, audit them before installation and document why execution is necessary.

  5. Run installation and the CLI as an unprivileged, isolated user. Do not recommend sudo npm install -g, and consider a container or sandbox with only the required filesystem and network access.

  6. Provide an approved-version policy and controlled upgrade process. Review release changes before updating the pinned version.

  7. Keep ADKIT_API_KEY out of broadly inherited environments where possible. Supply it only to the required process, limit its permissions, rotate it after suspected compromise, and avoid exposing it to package installation lifecycle scripts.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
86% confidence
Finding

The trigger 'create campaign' begins with a generic built-in verb and can shadow broader 'create' command patterns. In a skill capable of operational ad account changes, this raises the likelihood that a normal request to create something will dispatch into this skill unexpectedly and initiate campaign-building workflows.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
88% confidence
Finding

The trigger 'create ad' is especially collision-prone because it is short, generic, and starts with the built-in-style verb 'create'. Given the skill's ability to generate and manage ad objects, accidental invocation could lead to draft creation, uploads, or downstream publishing flows in the wrong context.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
81% confidence
Finding

The trigger 'search interests' overlaps with a generic 'search' command pattern and could misroute normal audience research or informational queries into this operational skill. While less immediately dangerous than publish actions, it still creates confusion and may expose connected ad account capabilities unnecessarily.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
92% confidence
Finding

The trigger 'run ads' conflicts with a generic 'run' command and is dangerous in this context because it semantically implies launching paid advertising activity. Even though the skill says drafts should not publish without approval, accidental invocation into an execution-oriented ads tool increases the risk of unintended campaign setup or progression toward live spend.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Triggers like 'ads mcp' and 'ads agent' are ambiguous and could refer to many unrelated tools or general discussion about ads. This ambiguity can cause the wrong skill to load in benign conversations, which is risky here because the skill is designed to manage drafts, media uploads, and campaign execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes broad, common ad-related phrases such as 'add keywords', 'keyword research', 'ad library', and 'generate ad' that are likely to match ordinary user requests. Because this skill can execute ad operations and route users into operational flows, overbroad invocation increases the chance of unintended activation and action-taking in sensitive advertising accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation describes immediate publish behavior via --publish without clearly warning that this can make ads live, spend budget, and alter external accounts. In an agent context, that omission increases the risk of accidental real-world actions because operators may treat the command as a routine creation step rather than an irreversible financial action.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest explicitly limits the skill away from copywriting and creative advice, yet the documented behavior includes passing full API request bodies and using raw platform flows that support ad creation workflows beyond the constrained commands. Combined with the manifest trigger 'generate ad' and the documented 'Create an ad (media + copy)' command, this indicates the skill materially supports ad-content generation/creation rather than only operational management.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Documenting raw platform API access inside a managed ads skill expands the effective capability far beyond the curated commands and safety boundaries implied by the skill description. This can enable arbitrary high-impact account mutations, unsupported workflows, or misuse of connected ad credentials without the guardrails that purpose-built commands would normally enforce.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Raw platform API access is presented without a prominent warning that it may perform arbitrary, high-impact changes across connected advertising accounts. Because this bypass path can reach unsupported native resources and multi-resource workflows, the absence of safety messaging and confirmation materially raises the chance of destructive or costly actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.