marketing-meta-ads-manager
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md의 운영 워크플로우는 사용자가 내는 자연어 “운영 의도/목표/대상/예산/기간/소재”를 받아 MCP로 생성·수정·예산·온오프를 수행하며, 이는 outsider(사용자) 입력이 LLM에 직접 제공되는 런타임 경로라서 간접 프롬프트 인젝션에 중간 위험입니다(기존 특정 항목을 선택해 읽는 구조가 아니라, 사용자의 임의 텍스트가 필수 입력입니다).
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed to perform live ad operations including creating/modifying campaigns and—critically—setting and adjusting ad budgets and payment/billing actions. It defines permission tiers including a "financial" scope, requires OAuth scopes like ads_management, and repeatedly states that write/예산/financial actions (예산 설정·조정, 결제·청구 관련 동작) are executed via the MCP endpoint. Because it provides API-backed budget control and payment-related operations (not merely read-only or generic browsing), it grants direct financial execution capability.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata