Back to skill

Security audit

广告洞察中枢

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent AdMapix API helper with disclosed curl/API-key use, local caching, and export behavior, with no hidden install or destructive actions found.

Install only if you intend to use AdMapix and are comfortable giving the agent curl/exec access and an ADMAPIX_API_KEY environment variable. Prefer explicit export paths, avoid overwriting existing files, and periodically review or delete ~/.admapix-cache if retained ad intelligence data is sensitive.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill instructs users to write paginated results to a local file but does not provide a clear safety warning, path restriction, or consent requirement around local data modification. In agent contexts with file and exec capabilities, vague write guidance can lead to unintended overwrites, sensitive data persistence, or writing into unsafe locations if the agent extrapolates behavior.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
Advertising generic file write capability without defining scope, safe destinations, overwrite rules, or consent boundaries is risky in an agent-execution environment. Even absent explicit malicious instructions, such broad capability descriptions can normalize unsafe local modifications and increase the chance of accidental persistence of API-derived or sensitive data.

Static analysis

No suspicious patterns detected.