google-ads

Fail

Audited by Snyk on Aug 26, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly tells the agent to read and display the user's Google Ads config (e.g., "cat ~/.google-ads.yaml") and references required API/OAuth credentials, which would expose API keys/OAuth secrets verbatim if executed or returned by the LLM.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In Browser Automation Mode, the workflow reads free-form UI table/filters content from the user’s authenticated Google Ads account via ads.google.com/aw/* (e.g., campaigns/keywords/snapshots), so outsider-authored text submitted into that account’s entities can be ingested.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly provides actions that change Google Ads account state and therefore can directly affect ad spend. It supports Browser Automation steps to "Pause" campaigns/keywords (click Edit → Pause) and an API-mode example that builds and sends mutate operations to set AdGroupCriterion status to PAUSED. The documentation also recommends changing budgets (e.g., "INCREASE: Branded budget"), indicating intent to modify spending. These are direct ad-spend management actions (covered by the "Managing Ad Spend Budgets" category), not mere read-only reporting or generic automation.

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 11:03 PM
Issues
3
Security Audit — snyk — google-ads