linkedin-ads

Warn

Audited by Snyk on May 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). This skill, per SKILL.md, directly uses the Membrane connector to fetch LinkedIn Ads data (e.g., list-creatives, get-creative, get-ad-analytics) and thus ingests third-party, user-generated content from LinkedIn that the agent reads and could materially influence its actions.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a specific LinkedIn Ads integration exposing actions like create-ad-account, create-campaign, update-campaign, update-ad-account and delete campaign objects via the Membrane CLI. Those action types are not generic view-only endpoints — they allow mutation of ad accounts and campaigns, which typically include settings for budgets and spend. The doc explicitly lists update/create actions (i.e., "Update Campaign") which meet the criterion "Managing Ad Spend Budgets (specifically the API to update the budget, not just viewing ads)". Because this is a targeted advertising integration (not a generic browser or HTTP tool) that can modify campaign/account configurations (and thus ad spend), it constitutes direct financial execution authority for ad budgets.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 1, 2026, 03:09 PM
Issues
2
Security Audit — snyk — linkedin-ads