Back to skill

Security audit

Meta Ads Api

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherently about managing Meta ads, but it gives agents live ad-changing authority while recommending unsafe token handling and broad logging of sensitive ad data.

Install only with tight controls: prefer read-only tokens unless writes are truly needed, use Authorization headers rather than URL tokens, require explicit approval before any create/update/pause/scale action, keep new objects paused, and disable or redact full response logging.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:28
Finding

Access Token Permitted in URL Query Strings

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 28-38
Vulnerability Type: Credential exposure through query-string authentication
Risk Level: Medium

Vulnerable Code

text
## Authentication

### Method

Use access token in query or header:

Authorization: Bearer <ACCESS_TOKEN>

or

?access_token=<ACCESS_TOKEN>

Technical Analysis

The Skill explicitly permits a Meta access token to be placed in a URL query parameter. Although transmitting the token to the declared Meta Graph API is necessary for the Skill's functionality, query strings are an unnecessarily exposed authentication channel.

Complete URLs are commonly captured by reverse proxies, API gateways, HTTP clients, monitoring platforms, debugging output, shell history, and application logs. Anyone with access to such records could recover the token. This also conflicts with the Skill's later instruction to never expose access tokens.

The token's effective capabilities depend on its assigned permissions. The documented permissions include ads_read and ads_management, which can provide access to confidential advertising data and permit campaign modifications.

Attack Path

  1. The agent follows the documented query-string authentication option.
  2. It constructs a request containing ?access_token=<ACCESS_TOKEN>.
  3. An intermediary, HTTP client, monitoring service, or logging component records the complete URL.
  4. A party with access to those records extracts the reusable token.
  5. The party submits requests to the Meta Marketing API using the stolen token.
  6. Subject to the token's scope, account access, and expiration, the party reads advertising information or modifies campaigns.

Impact Assessment

A compromised token may expose campaign names, identifiers, performance metrics, spending information, creatives, and other advertising-account data. If the token has ads_management, an attack ...[truncated 183 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove support for access_token query parameters.
  • Require Authorization: Bearer <ACCESS_TOKEN> for every authenticated request.
  • Explicitly prohibit credentials in URLs, pagination links, error messages, and diagnostic output.
  • Configure HTTP clients, proxies, and monitoring systems to redact the Authorization header.
  • Use short-lived or appropriately rotated tokens where operationally possible.
  • Restrict each token to the minimum required permissions; use ads_read alone for read-only workflows.
  • Revoke and rotate any token suspected of appearing in URL or request logs.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:271
Finding

Unrestricted API Response Logging May Expose Sensitive Advertising Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 271-275
Vulnerability Type: Excessive logging of sensitive API responses
Risk Level: Medium

Vulnerable Code

text
## Reliability

* Retry failed requests (max 3)
* Log all API responses
* Detect empty responses

Technical Analysis

The instruction to log all API responses is overly broad and does not require redaction, data minimization, retention limits, secure storage, or access controls. Meta Marketing API responses may contain confidential campaign information, account identifiers, performance and spending data, creatives, and pagination metadata.

The risk is compounded by the separately documented query-string authentication option. If credential-bearing URLs are returned or retained in pagination or diagnostic metadata, unrestricted logging could persist reusable authentication material. Even where no token is present, complete response logging exceeds what is normally necessary for reliability monitoring.

Logging status codes, request identifiers, sanitized error categories, and aggregate operational metrics would meet the stated reliability purpose with substantially less exposure.

Attack Path

  1. The agent requests campaign, advertisement, or insight data from the Meta API.
  2. The API returns sensitive advertising data and potentially pagination metadata.
  3. Following the Skill instruction, the implementation records the complete response.
  4. Logs are retained in a local file, centralized logging service, debugging trace, or agent transcript without mandated redaction or access restrictions.
  5. A user, operator, service account, or attacker with log access retrieves the recorded information.
  6. The exposed data is used for unauthorized business intelligence; if reusable credentials are present, they may also be used for unauthorized API access.

Impact Assessment

The issue can disclose advertising-account struct ...[truncated 479 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace “Log all API responses” with a requirement to log only minimum operational metadata.
  • Limit logs to HTTP status codes, sanitized error categories, correlation IDs, retry counts, and request timing.
  • Redact access tokens, authorization headers, full URLs, query parameters, account IDs, audience information, creatives, and pagination URLs.
  • Do not log successful response bodies unless explicitly required for a documented debugging event.
  • Apply encryption at rest, least-privilege log access, retention limits, and auditable access controls.
  • Disable verbose logging by default and require explicit, time-limited authorization to enable it.
  • Add tests that verify secrets and sensitive response fields cannot enter logs.
  • Review existing logs and securely delete or restrict any records containing credentials or confidential advertising data.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

Method

Use access token in query or header:

text
Authorization: Bearer <ACCESS_TOKEN>

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 263)May include surrounding context.

md
## Safety

* Always create campaigns as `PAUSED`
* Never expose access tokens
* Validate all IDs before use

## Efficiency

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill includes write operations that can create ads, ad sets, campaigns, and change campaign status, but it does not clearly warn that these actions modify live ad account resources and can lead to real financial spend or operational disruption. In an agent context, that omission increases the chance of unsafe autonomous actions being taken without explicit user confirmation or guardrails.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill contradicts itself by warning to never expose access tokens while earlier instructing that tokens may be placed in the URL query string. Query parameters are commonly logged by clients, proxies, browser history, and monitoring systems, which increases the risk of credential leakage and unauthorized access to the ad account.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.