pp-amazon-ads

Warn

Audited by Snyk on Jul 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.85). The skill's required install commands fetch and execute remote code at setup/runtime (e.g., "npx -y @mvanhorn/printing-press-library install amazon-ads --cli-only" and "go install github.com/mvanhorn/printing-press-library/library/commerce/amazon-ads/cmd/amazon-ads-pp-cli@latest"), so it relies on external content that is executed locally.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill exposes CLI commands that can create and update advertising budgets and budget rules (e.g., create/update budget rules for Sponsored Brands/Display/Products) and includes an "apply" mode that performs mutations (sends updates) such as campaign budget updates. Those capabilities constitute direct ad-spend/budget management (Direct Financial Execution).

Issues (2)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 11, 2026, 02:13 AM
Issues
2
Security Audit — snyk — pp-amazon-ads