Back to skill

Security audit

Paid Ads

Security checks across malware telemetry and agentic risk

Overview

This is a coherent paid-ads guidance skill, but it gives the agent broad ad-account authority without clear approval gates for actions that can spend money or share customer data.

Install only if you want supervised paid-advertising help. Treat it as planning guidance by default; do not let it log into ad platforms, launch or edit campaigns, change budgets, or upload customer/contact lists unless you have explicitly reviewed and approved the exact account, data, spend, and changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description includes many broad trigger phrases such as 'ad budget,' 'ad spend,' and 'should I run ads,' which can overlap with ordinary business discussion and cause the skill to activate in contexts where the user did not explicitly request paid-ads help. Over-broad routing increases the chance that the agent applies the wrong skill, pulls in account-related guidance unnecessarily, or proceeds toward ad-platform actions without sufficient user confirmation.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill states that the agent has 'direct access to ad platform accounts' but does not require explicit authorization, preview/dry-run behavior, change summaries, or warnings before account-impacting actions. In this context, that is particularly risky because advertising platforms control budgets, campaigns, targeting, and tracking, so mistaken or premature actions can cause immediate financial loss, policy violations, data exposure, or disruption of live campaigns.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The eval explicitly rewards triggering on a vague, casual request ('we want to run retargeting ads...') without requiring clear scoping boundaries beyond general paid-ads intent. In isolation this is not code-execution dangerous, but it can cause over-broad skill activation, misrouting adjacent requests, and increased unintended access to paid-ads guidance when user intent is ambiguous.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The guidance recommends uploading customer email lists for ad targeting without any mention of consent, lawful basis, platform policy requirements, minimization, or secure handling. In a paid-ads skill, this is contextually plausible business advice, but omission of privacy safeguards can lead users to misuse personal data in violation of privacy law, contractual terms, or internal policy.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The custom audience section advises uploading emails and phone numbers and refreshing them regularly, but provides no warning about consent, notice, data-sharing implications, or restrictions on sensitive personal data. Because this file is operational guidance for ad targeting, users may treat it as complete instructions and unknowingly process personal data in a non-compliant way.

Missing User Warnings

Low
Confidence
81% confidence
Finding
The ABM guidance suggests uploading target account lists with no mention of authorized sourcing, contractual restrictions, or governance over associated company/contact data. This is less severe than direct consumer email/phone uploads because company lists may be non-personal in some cases, but it can still facilitate misuse of personal contact data or improperly sourced prospect information.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The checklist instructs users to deploy broad web tracking, upload customer lists, and enable server-side collection features such as CAPI without any accompanying privacy, consent, retention, or lawful-basis guidance. In a paid-ads skill, this is operationally plausible, but omitting privacy controls can lead users to implement non-compliant data collection and sharing practices across ad platforms.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.