linkedin-ads
Warn
Audited by Snyk on May 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). This skill, per SKILL.md, directly uses the Membrane connector to fetch LinkedIn Ads data (e.g., list-creatives, get-creative, get-ad-analytics) and thus ingests third-party, user-generated content from LinkedIn that the agent reads and could materially influence its actions.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a specific LinkedIn Ads integration exposing actions like create-ad-account, create-campaign, update-campaign, update-ad-account and delete campaign objects via the Membrane CLI. Those action types are not generic view-only endpoints — they allow mutation of ad accounts and campaigns, which typically include settings for budgets and spend. The doc explicitly lists update/create actions (i.e., "Update Campaign") which meet the criterion "Managing Ad Spend Budgets (specifically the API to update the budget, not just viewing ads)". Because this is a targeted advertising integration (not a generic browser or HTTP tool) that can modify campaign/account configurations (and thus ad spend), it constitutes direct financial execution authority for ad budgets.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata