Back to skill

Security audit

Ad Creative Intel Free

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent ad intelligence API helper, with the main consideration being that searches and filters are sent to a third-party service.

Install only if you are comfortable sending ad search keywords, competitor names, app identifiers, regions, and related query filters to the Ad Creative Intel API. Use a scoped API key where possible, keep it in environment or platform secret storage, and avoid entering confidential or personal data unless your organization permits that sharing.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill prominently describes its capabilities but does not clearly warn users up front that their prompts and query parameters will be transmitted to a third-party external API. In a data-analysis workflow, users may paste competitor names, campaign terms, or other sensitive business context, causing unintended data disclosure to the remote service.

Static analysis

No suspicious patterns detected.