Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/keyword-report.js:9
Security audit
Security checks across malware telemetry and agentic risk
This skill uses disclosed Amazon Ads credentials to fetch reporting and keyword bid data, with no evidence of hidden persistence, destructive changes, or unrelated data sharing.
Install only if you intend to let these scripts use your Amazon Ads OAuth credential file for the configured advertising profile. Review the credential scope, expect Amazon network calls, treat the current implementation as EU-focused, and do not rely on the documented campaign-level commands unless those missing scripts are supplied and reviewed.
65/65 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal