Back to skill

Security audit

Detect & Refresh Ad Copy Fatigue with AI Analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its advertising-analysis purpose, but it asks for broad ad-platform credentials and can schedule or launch business-impacting campaign changes without enough privacy, scoping, or rollback guidance.

Review this carefully before installing. Use the narrowest possible ad-platform scopes, prefer OAuth over pasted raw keys where available, avoid granting campaign-mutation permissions unless you intend automated A/B test creation, and confirm where credentials, campaign metrics, generated copy, Slack alerts, and OpenAI-bound data will be stored or logged.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill requires multiple high-privilege advertising and AI API credentials and includes example commands and environment variables for handling them, but it does not provide any explicit privacy, storage, redaction, or data-sharing warning to the user. Because the skill connects to ad platforms, account IDs, and optional Slack webhooks, users may expose sensitive business data or secrets to the skill and downstream services without understanding how that data is handled.

Static analysis

No suspicious patterns detected.