Back to skill

Security audit

Ad Creative Intel Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent ad intelligence API helper, with the main consideration being that searches and filters are sent to a third-party service.

Install only if you are comfortable sending ad search keywords, competitor names, app identifiers, regions, and related query filters to the Ad Creative Intel API. Use a scoped API key where possible, keep it in environment or platform secret storage, and avoid entering confidential or personal data unless your organization permits that sharing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill prominently describes its capabilities but does not clearly warn users up front that their prompts and query parameters will be transmitted to a third-party external API. In a data-analysis workflow, users may paste competitor names, campaign terms, or other sensitive business context, causing unintended data disclosure to the remote service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.