competitor-ad-teardown

Fail

Audited by Snyk on Aug 22, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The skill includes explicit examples showing an Authorization header with Bearer <appeeky-key> and mentions an Appeeky API key / X-Meta-Ad-Library-Token, which encourages embedding real secret tokens into generated API requests or curl commands, creating an exfiltration risk if a real key is provided.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The skill’s runtime workflow ingests competitor creative text/media content from the Appeeky Meta Ad Library via meta_app_ad_intelligence, meta_ads_search, and meta_ads_page_ads (which are derived from outsider-authored Meta ads/search inputs).

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 22, 2026, 10:18 PM
Issues
2
Security Audit — snyk — competitor-ad-teardown