Back to skill

Security audit

Ad Campaign Optimizer

Security checks for vulnerabilities and agentic risk

Overview

The skill is not malicious, but it needs review because it describes automating paid ad creation and budget optimization without clear safeguards or confirmation steps.

Review carefully before installing in an agent that can access real ad accounts. Use it only with explicit account scoping, preview or dry-run behavior, budget caps, and human confirmation before creating campaigns, changing targeting, or increasing spend.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill advertises automatic ad creation, optimization, and multi-platform campaign actions that can directly change live advertising configuration and spend, but it provides no warning, approval checkpoint, or disclosure about external financial impact. In this context, a user could trigger real budget-consuming actions or materially alter campaign targeting/performance without realizing the operational and monetary consequences.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The quick-start section gives executable commands for creating ads and optimizing campaigns immediately, but it does not warn that these actions may spend money, affect production campaigns, or propagate to third-party platforms. This makes unsafe use more likely because users may copy and run commands assuming they are demonstrations rather than live-impact operations.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest description 'AI-powered skill for productivity' is overly generic and does not clearly constrain the skill's intended purpose or invocation boundaries. Broad descriptions can cause unintended routing or over-selection of the skill in contexts it was not designed for, increasing the risk of misuse or unsafe behavior when integrated into agent ecosystems.

Static analysis

No suspicious patterns detected.