Back to skill

Security audit

Adagent Google Ads

Security checks for vulnerabilities and agentic risk

Overview

This Google Ads connector is coherent, but it uses a password-like MCP link with authority to read and change ad accounts, so it needs careful review before installation.

Install only if you trust AdAgent with your Google Ads account. Treat the MCP link as a secret, verify the Google OAuth permissions, confirm account, budget, geography, language, and final URL before any campaign creation or enablement, and revoke or regenerate access immediately if the link is exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:14
Finding

Credential-Bearing MCP URL Is Vulnerable to Disclosure and Replay

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger description includes broad phrases like 'keyword research', 'search ads', and 'ad performance', which can match routine informational or marketing queries without clear user intent to manage a Google Ads account. In a skill that can read account data and create or modify campaigns through an authenticated MCP link, overbroad activation increases the risk of unintended tool use and exposure of sensitive account information or state-changing actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The keyword research example hard-codes Taiwan and Chinese without indicating that these are merely examples or requiring user choice. This can steer the agent toward processing requests in an unintended market or language context, producing misleading ad research and potentially causing privacy or business-context errors if applied automatically to a user's account workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The campaign creation example hard-codes a specific location and language, which may cause a campaign to be prepared for the wrong market if the agent follows the example by default. In this skill context, even though campaigns start paused, generating campaigns with incorrect targeting can still lead to operational mistakes and accidental activation of misconfigured ads.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.