Back to skill

Security audit

Amazon Ads API

Security checks for vulnerabilities and agentic risk

Overview

The skill is a small Amazon Ads helper that uses user-provided credentials to read profiles and campaign summaries, with some documentation overreach but no hidden, destructive, or unrelated behavior found.

Install only if you are comfortable giving the agent access to an Amazon Ads refresh token and campaign data. Store amazon-ads-api.json outside version control with restricted permissions, prefer the minimum Amazon Ads permissions needed, and treat --out exports as sensitive business data. Expect read/list and summary behavior from this version, not full campaign, keyword, bid, or optimization management.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented behavior overstates capabilities and omits side effects: it claims campaign management and performance access, but the described commands only list profiles/campaigns, summarize budgets, and optionally write output to a local file. This mismatch can mislead users and automated policy systems about what the skill actually does, reducing informed consent and potentially allowing undeclared data handling such as local file output.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
node scripts/ads.js --profiles

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
node scripts/ads.js --profiles

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
node scripts/ads.js --profiles

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
node scripts/ads.js --profiles

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
node scripts/ads.js --profiles

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
node scripts/ads.js --profiles

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises campaign management and daily optimization for any advertiser account but does not warn that the skill can modify live Amazon Ads resources. This increases the risk of unintended destructive or costly actions by users or downstream agents who may treat the skill as informational rather than write-capable, especially in autonomous workflows.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents network access to Amazon Ads and use of environment variables for credential loading, but it does not declare an explicit tool scope such as permissions or allowed-tools. That omission weakens security boundaries because an agent may be granted broader capabilities than users expect, especially in a skill that handles secrets and performs external API calls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to place client secrets and refresh tokens in a local JSON file without any warning about secure storage, access controls, or accidental exposure. In a skill that accesses advertising accounts, leaked credentials could allow unauthorized reading of account data and potentially actions against advertiser resources depending on token scope.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ads.js (reported line 25)May include surrounding context.

js
async function getAccessToken() {
  const creds = getCreds();
  const res = await fetch('https://api.amazon.com/auth/o2/token', {
    method: 'POST',
    headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
    body: new URLSearchParams({

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ads.js (reported line 25)May include surrounding context.

js
async function getAccessToken() {
  const creds = getCreds();
  const res = await fetch('https://api.amazon.com/auth/o2/token', {
    method: 'POST',
    headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
    body: new URLSearchParams({

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/ads.js:12

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/ads.js:32