Back to skill

Security audit

Ads Optimizer Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Amazon Ads helper that uses user-provided credentials to fetch account data, with some overstated documentation but no hidden persistence or unrelated data handling.

Install only if you are comfortable giving the skill access to an Amazon Ads credential file. Use a credential limited to the advertiser accounts and permissions you intend, store the credential file carefully, and treat --out exports as sensitive campaign/account data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill description overstates its behavior and omits important side effects, including writing fetched campaign data to a local file via --out. This mismatch can mislead users and automated policy systems into granting trust or permissions under false assumptions, increasing the risk of unintended data exposure or unsafe execution in environments handling advertiser account data.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
node scripts/ads.js --profiles

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
node scripts/ads.js --profiles

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
node scripts/ads.js --profiles

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
node scripts/ads.js --profiles

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
node scripts/ads.js --profiles

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
node scripts/ads.js --profiles

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares executable behavior that uses environment variables and network access, but it does not declare any tool scope such as permissions or allowed-tools. This weakens policy enforcement and reviewability, because an agent may invoke capabilities to read secrets and contact external Amazon endpoints without explicit authorization in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script reads a credentials file from a path in AMAZON_ADS_PATH or a local default file and then parses secrets from it, but there is no visible warning, prompt, or explanatory comment disclosing that sensitive advertising API credentials will be accessed. Because this is a code file handling credentials, some user-facing or documented disclosure is expected under the rule when no other warning is present in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The token request sends refresh_token, client_id, and client_secret to Amazon over HTTP(S), and subsequent API calls transmit authenticated account data, but the script provides no user-facing disclosure that sensitive data will be sent to external Amazon endpoints. The usage header describes commands only and does not warn about outbound authenticated requests.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ads.js (reported line 25)May include surrounding context.

js
async function getAccessToken() {
  const creds = getCreds();
  const res = await fetch('https://api.amazon.com/auth/o2/token', {
    method: 'POST',
    headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
    body: new URLSearchParams({

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ads.js (reported line 25)May include surrounding context.

js
async function getAccessToken() {
  const creds = getCreds();
  const res = await fetch('https://api.amazon.com/auth/o2/token', {
    method: 'POST',
    headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
    body: new URLSearchParams({

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

When --out is supplied, the script writes fetched campaign data to disk, but there is no prior warning in comments, help text, or runtime messaging that local files may be created containing account information. The only message appears after the write has already occurred.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/ads.js:12

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/ads.js:32