competitor-ad-teardown
Fail
Audited by Snyk on Aug 22, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The skill includes explicit examples showing an Authorization header with
Bearer <appeeky-key>and mentions an Appeeky API key / X-Meta-Ad-Library-Token, which encourages embedding real secret tokens into generated API requests or curl commands, creating an exfiltration risk if a real key is provided.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s runtime workflow ingests competitor creative text/media content from the Appeeky Meta Ad Library via
meta_app_ad_intelligence,meta_ads_search, andmeta_ads_page_ads(which are derived from outsider-authored Meta ads/search inputs).
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata