Back to skill

Security audit

广告洞察中枢LITE

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches an AdMapix advertising lookup tool, but it also declares or advertises file-writing and broad automation capabilities that are not clearly needed for that purpose.

Review this before installing. It is not showing evidence of theft, destruction, or hidden persistence, but you should only grant the permissions needed for AdMapix API queries. Avoid enabling local write access unless you have a specific output-file workflow, keep ADMAPIX_API_KEY in the environment rather than chat, and inspect generated curl commands before running them.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is presented as a narrow AdMapix query tool, but later claims broad automation and file-processing capabilities that exceed that stated scope. This scope expansion increases the chance an agent will invoke write or generic automation behaviors unrelated to the user’s request, violating least privilege and enabling unintended data modification or misuse.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Claiming read/parse/write file capability for an advertising-intelligence lookup skill is unnecessary and dangerous because it normalizes write access without a clear business need. In an agent environment, this can cause overbroad tool selection and permit local file modification, persistence, or data exfiltration workflows beyond simple API querying.

Intent-Code Divergence

Medium
Confidence
81% confidence
Finding
The document contains contradictory capability statements: one section denies endpoint orchestration while others advertise full-process automation and multi-interface aggregation. Such inconsistencies can mislead an agent or operator about what autonomous behaviors are authorized, increasing the risk of over-execution or unsafe assumptions during tool use.

Static analysis

No suspicious patterns detected.