google-ads
Fail
Audited by Snyk on Aug 26, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill explicitly tells the agent to read and display the user's Google Ads config (e.g., "cat ~/.google-ads.yaml") and references required API/OAuth credentials, which would expose API keys/OAuth secrets verbatim if executed or returned by the LLM.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In Browser Automation Mode, the workflow reads free-form UI table/filters content from the user’s authenticated Google Ads account via ads.google.com/aw/* (e.g., campaigns/keywords/snapshots), so outsider-authored text submitted into that account’s entities can be ingested.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly provides actions that change Google Ads account state and therefore can directly affect ad spend. It supports Browser Automation steps to "Pause" campaigns/keywords (click Edit → Pause) and an API-mode example that builds and sends mutate operations to set AdGroupCriterion status to PAUSED. The documentation also recommends changing budgets (e.g., "INCREASE: Branded budget"), indicating intent to modify spending. These are direct ad-spend management actions (covered by the "Managing Ad Spend Budgets" category), not mere read-only reporting or generic automation.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata