Back to skill

Security audit

Adagent Facebook Ads

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for managing Meta ads, but it asks users to connect a third-party service with persistent, high-impact ad-account authority through a credential-like MCP link.

Install only if you are comfortable granting AdAgent third-party access to your Meta ad accounts. Treat the MCP URL as a password, connect only accounts you intend the agent to manage, confirm any budget or activation change manually, and make sure you know how to revoke the Facebook authorization and rotate the connector if it is exposed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:9
Finding

Credential-Bearing MCP URL Creates a Bearer Secret Exposure Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:9-12, 20, 24, 35-38
Vulnerability Type: Credential exposure through URL-based authentication
Risk Level: High

Vulnerable Code

yaml
metadata:
  openclaw:
    emoji: "📣"
    homepage: https://adagent.10xboost.org
    requires:
      config:
        - MCP Connector link from adagent.10xboost.org (contains embedded auth token)
markdown
- **MCP link is a credential**: Your MCP Server URL (`https://adagent.10xboost.org/api/mcp/fb-ads/{user_id}/mcp`) contains your user ID for credential lookup. Treat it like a password — do not share it publicly.
markdown
- **No local credentials**: No local API keys, environment variables, or secrets are needed. All auth is embedded in the MCP link.
markdown
3. **Get your MCP link**: Copy your Facebook Ads MCP Server URL from the dashboard
4. **Add to Claude**: Paste the MCP link as a Connector — no install, no API key needed

Technical Analysis

The skill explicitly states that authentication is embedded in the MCP URL and that the URL must be treated as a password. URL-based bearer credentials are vulnerable to incidental disclosure because complete URLs may be retained in browser history, connector configuration, application telemetry, HTTP access logs, reverse-proxy logs, diagnostic exports, screenshots, or support records.

The documentation is also ambiguous about the credential mechanism. The metadata says that the link contains an embedded authentication token, while the security section says that it contains a user ID used for credential lookup. If the user ID or opaque path is sufficient to authorize requests, possession of the URL effectively grants bearer access. No secondary authentication, expiration, client binding, or request-level authorization control is documented.

The endpoint exposes financially consequential operations, including campaign creation, budget management, and advertisement activation. Consequentl ...[truncated 1552 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace URL-embedded credentials with short-lived access tokens transmitted in an Authorization header.
  2. Ensure that the URL itself is non-secret and cannot independently authorize access.
  3. Make tokens narrowly scoped, time-limited, revocable, and bound to the intended user or connector client where practical.
  4. Redact authentication material from application, proxy, telemetry, and diagnostic logs.
  5. Provide users with an immediate mechanism to revoke and rotate MCP credentials.
  6. Require explicit user confirmation for operations that activate advertisements, modify budgets, or otherwise incur spending.
  7. Add configurable spending limits and transaction thresholds.
  8. Clearly document whether the URL contains a user identifier, an authentication token, or both.
  9. Do not allow a predictable user identifier to function as authorization.
  10. Monitor for anomalous clients, locations, and financially consequential operations, and notify users when sensitive actions occur.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Privileged Advertising Operations Are Delegated to an Unverifiable Third-Party MCP Service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:18-29, 34-38
Vulnerability Type: Privileged third-party service and supply-chain trust risk
Risk Level: Medium

Vulnerable Code

markdown
## Security & Data Handling

- **MCP link is a credential**: Your MCP Server URL (`https://adagent.10xboost.org/api/mcp/fb-ads/{user_id}/mcp`) contains your user ID for credential lookup. Treat it like a password — do not share it publicly.
- **Token scope**: The service uses your Facebook OAuth token to access your ad accounts. It can create/modify campaigns, ad sets, and ads, manage budgets, and read performance data.
- **Token storage**: Your Facebook tokens are encrypted with Fernet (AES-128-CBC + HMAC) and stored in MongoDB. They are never exposed in API responses.
- **Token expiry**: Facebook long-lived tokens expire after ~60 days. Use `refresh_token` to extend when needed.
- **Multi-tenant isolation**: Each request is scoped to your user credentials via ASGI middleware. You can only access your own ad accounts.
- **No local credentials**: No local API keys, environment variables, or secrets are needed. All auth is embedded in the MCP link.
- **Third-party service**: This skill relies on [AdAgent](https://adagent.10xboost.org), an AI-powered ad management platform.
markdown
## Prerequisites

1. **Sign up** at [adagent.10xboost.org](https://adagent.10xboost.org) with Google
2. **Connect Facebook Ads** — authorize AdAgent to access your Facebook Ad accounts
3. **Get your MCP link**: Copy your Facebook Ads MCP Server URL from the dashboard
4. **Add to Claude**: Paste the MCP link as a Connector — no install, no API key needed

Technical Analysis

The skill delegates all sensitive functionality to the remote adagent.10xboost.org service. Users must authorize that service to access Facebook advertising accounts, after which the service stores Facebook OAuth tokens and can create or modify campaigns, ad sets, advertisements, and budge ...[truncated 2442 chars]

Remediation
View remediation

Remediation Suggestions

  1. Publish auditable server and client source code or obtain an independent security assessment of the hosted service.
  2. Document the exact Facebook OAuth permissions requested and remove permissions that are not essential.
  3. Separate read-only reporting permissions from campaign-management and spending permissions.
  4. Require explicit, transaction-specific user confirmation before enabling advertisements or changing budgets.
  5. Implement account-level spending limits, per-operation thresholds, and emergency suspension controls.
  6. Use strong tenant identifiers and perform server-side authorization for every request and every advertising account object.
  7. Test tenant isolation through automated negative-access tests and periodic penetration testing.
  8. Provide transparent token retention, encryption, rotation, deletion, and revocation procedures.
  9. Pin clients to a reviewed API version and publish security-relevant change notifications.
  10. Maintain immutable audit logs for token use, campaign changes, budget changes, and activation events.
  11. Notify users of sensitive operations and anomalous access.
  12. Allow users to revoke the Facebook authorization directly and invalidate all corresponding MCP sessions immediately.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises broad trigger phrases like 'Facebook Ads', 'Meta Ads', 'ad targeting', and 'ad performance', which can cause the agent to invoke this high-impact skill for generic marketing discussions rather than explicit account-management requests. Because the skill can create and modify campaigns and spend budget through an embedded credentialed MCP link, overbroad activation increases the chance of unintended privileged actions or unnecessary exposure of advertising account data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The only explicit compliance tool is get_taiwan_regulation_status, which introduces a locale-specific policy focus in a general Facebook Ads skill. The file does not clearly state that the skill is Taiwan-specific or that Taiwan compliance checks are optional based on the user's region.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.