ad-creative

Fail

Audited by Snyk on Aug 7, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). These URLs point to a personal/site-hosted desktop app and its GitHub repo (voicebox.sh and jamiepine/voicebox[.git]) which distribute installers/source outside major vendor channels and therefore represent a higher-risk download/source for potential malware distribution.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill includes explicit platform integrations and CLI commands for managing ad campaigns (not just reading data). Notably it lists "google-ads campaigns create" and instructs using available ads platform integrations to "manage campaigns" and "upload to platform." Creating or managing ad campaigns is an explicit management operation that can alter ad spend/budgets on advertising platforms, which falls under Direct Financial Execution authority per the policy.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 7, 2026, 09:22 PM
Issues
2
Security Audit — snyk — ad-creative