Back to skill

Security audit

Ads Brain Planning Create Pipeline 1.0.0

Security checks across malware telemetry and agentic risk

Overview

This skill is a content-only ad planning workflow with disclosed guardrails and no hidden execution or persistence behavior.

Before installing, confirm this workflow is only connected to systems that require user confirmation before creating or launching ads, since the skill can prepare actionable campaign structures even though it does not execute creation itself.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill uses broad trigger phrases such as '帮我搭一个计划' and '给我出一个投放方案' to enter the create pipeline. In a conversational agent, overly broad routing can cause user requests that are actually exploratory, advisory, or optimization-oriented to be misclassified as creation intents, which may lead to generation of actionable campaign artifacts under the wrong context.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.