Back to skill

Security audit

Paid Ads

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate paid-ads skill, but it needs review because it implies live ad-account access and recommends privacy-sensitive tracking and customer-list uploads without clear approval or consent guardrails.

Use this skill mainly for strategy unless you add clear human approval before any live ad-account change. Before using its tracking, retargeting, or customer-list guidance, confirm legal permission, privacy notice and consent requirements, platform policy compliance, and avoid scraped, purchased, or unpermissioned contact data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation text includes many broad phrases such as 'should I run ads' and general advertising terminology, increasing the chance this skill is selected for loosely related business questions. Misrouting is less severe than code execution issues, but it can cause the agent to enter a high-impact workflow involving budgets, targeting, and external integrations when the user only wanted general advice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill text states the agent has 'direct access to ad platform accounts,' which expands expected behavior from advisory guidance into implied live account operation. In a paid ads context, that can lead to unauthorized campaign edits or spend changes if an orchestration layer trusts the skill narrative more than the manifest scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Claiming direct access to ad accounts without an accompanying warning or confirmation requirement is dangerous because actions in this domain can immediately spend money, alter campaigns, or affect attribution and customer acquisition. The surrounding skill content includes implementation-oriented guidance and tool links, which makes the omission more risky in context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON eval file is a manifest-type file, so vague-trigger checks apply. The expected output and assertion explicitly say the skill should 'trigger on casual phrasing,' but they do not define boundaries, exclusions, or specific trigger phrases, which could cause unintended activation on ordinary user requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guidance tells users to upload email lists for Customer Match retargeting and lookalike creation without any warning that customer contact data must be collected and used with valid consent and in compliance with platform policies and privacy laws. In a paid-ads skill, this omission is materially risky because it normalizes sharing personal data with ad platforms and can lead users to misuse customer data for advertising without proper notice, consent, or data-processing safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section recommends uploading customer emails and phone numbers and discusses match rates, but omits any disclosure that these are sensitive personal identifiers whose advertising use may require consent, notice, and lawful basis. Because this skill is specifically about audience targeting, the missing warning makes the advice more dangerous by directly encouraging privacy-sensitive ad practices in an operational playbook.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Referencing pixel-based custom audiences without any privacy warning implicitly endorses tracking users for ad targeting while ignoring consent, disclosure, and cookie/tracker compliance obligations. In the context of a paid advertising skill, this is not incidental technical detail; it is actionable advice that could cause unlawful or noncompliant behavioral tracking if followed as written.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The checklist directs implementers to enable sitewide Google tracking, enhanced conversions, GA4 audience sharing, remarketing, and customer match uploads without any warning to verify consent, lawful basis, data minimization, or regional privacy requirements. In a production marketing skill, this omission can directly lead users to deploy invasive tracking and customer-data use in ways that violate privacy laws or platform policies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section recommends Meta Pixel, Conversions API, event prioritization, extensive custom audiences, and customer list uploads, but omits warnings about consent, notice, hashing/upload requirements, and restrictions around sensitive data and regulated categories. Because Meta tracking and audience tooling are highly privacy-sensitive, users may treat the checklist as approval to collect and activate personal data without necessary safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The LinkedIn guidance includes Insight Tag deployment, conversion tracking, website retargeting, and uploads of company/contact lists for matched audiences, yet it provides no warning about permission to use uploaded data or privacy obligations for tracking. In a B2B advertising context, this can normalize using business and personal contact data for ad targeting without validating notice, consent, contractual rights, or suppression of restricted data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Twitter/X and TikTok sections advise installing pixels, creating conversion events, building tailored/custom audiences, and using customer lists without any mention of user awareness, consent, or privacy implications. The skill context makes this more dangerous because it is an operational setup checklist that users may follow verbatim when configuring live advertising systems, increasing the chance of noncompliant tracking and audience activation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.