openai-ads
Warn
Audited by Socket on Jul 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's ad-management capabilities are largely aligned with its stated purpose, but its credential and data flow are not purely first-party. Requiring users to connect an OpenAI Ads API key through Hyper MCP introduces a meaningful third-party trust boundary for sensitive advertising credentials and account operations. No direct malware indicators or hidden execution appear in the skill text, but the intermediary architecture makes it higher risk than a direct official API integration.
Confidence: 84%Severity: 58%
Audit Metadata