Back to skill

Security audit

Ad Insight Hub

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AdMapix API helper for advertising intelligence, with expected network calls, API-key use, and local caching.

Install only if you intend to use AdMapix and are comfortable giving the agent exec access for curl requests. Keep ADMAPIX_API_KEY in the environment, do not paste it into chat, and review cache/export locations before saving proprietary campaign or competitor research data on shared machines.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
77% confidence
Finding
The skill instructs writing exported query results to local files without an explicit warning or consent checkpoint at the point of use. Because advertising intelligence results may contain proprietary research outputs or sensitive business data, silent local persistence can create confidentiality, retention, and accidental disclosure risks on shared or managed systems.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.