Back to skill

Security audit

Hologres Ad Campaign

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its advertised Hologres ad workflow, but it asks for cloud storage/database authority and runs writable SQL templates in a way users should review carefully before installing.

Install only if you intentionally want a Hologres/OSS-based ad generation workflow. Use a pinned, reviewed hologres-cli version in an isolated environment, run with least-privileged Hologres and OSS/RAM roles, avoid pasting secrets, treat signed OSS URLs as private bearer links, and review or rewrite the SQL templates to use parameter binding or strict validation before running them against important data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned Third-Party CLI Dependency Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/sql-templates.md:46
Finding

SQL Injection Through Direct Substitution of User-Controlled Template Values

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation text uses very broad trigger phrases covering generic ad/video creation and ROI analysis scenarios, which can cause the skill to activate in contexts beyond the user's intent. Over-broad activation increases the chance that the agent will unnecessarily solicit infrastructure details or initiate SQL-centric workflows for ordinary creative requests, creating avoidable data exposure and unsafe tool use risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs collection of OSS bucket names, region endpoints, RAM role ARNs, and asset paths without any warning, minimization guidance, or safe-handling boundaries. These infrastructure identifiers can materially aid reconnaissance and, combined with misconfiguration or later leakage, increase the risk of unauthorized access attempts, privilege misuse, or exposure of internal storage topology.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description contains many broad trigger phrases around advertising, video generation, ROI analysis, and related workflows, which can cause the skill to activate in response to ordinary user discussions instead of clearly scoped requests. Over-broad activation increases the chance of unintended routing, exposing users to unexpected SQL-driven actions or analytics behavior they did not explicitly request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description is fully Chinese-language and appears to assume Chinese-language behavior without stating a locale constraint or user opt-in path. This can cause incorrect activation or mismatched responses for users in other languages, creating confusion and increasing the risk of unintended execution in multilingual environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The SQL templates send product materials and OSS/local file references to external AI generation functions (ai_gen, to_file) without any notice, consent, or data-classification guidance. In an ad-creation workflow, uploaded assets may include proprietary creative, customer data, or licensed media, so silent transmission to remote model services creates confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This section documents full ad-video generation through remote AI processing and explicitly instructs preserving signed video URLs containing access parameters such as Expires, OSSAccessKeyId, and Signature. Exposing or broadly sharing signed URLs can grant unintended access to generated media, and the lack of any warning increases the chance of accidental leakage of sensitive or proprietary campaign assets.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents all user-facing instructions and templates exclusively in Chinese. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue when no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Natural-language instructions and embedded prompt templates are Chinese-only throughout the file, which can impose a language constraint on users and downstream model behavior. The file does not offer an alternative language option or explain that the skill is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.