ads

Fail

Audited by Snyk on Jun 29, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.90). The prompt explicitly instructs the agent to run pre-request checks "silently" and to hide that fact from the user—an instruction to deceive about the agent's behavior, which is a hidden/deceptive directive outside normal transparent operation.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly exposes write APIs that change ad spend and bidding — i.e., direct controls over budget and bids. Notable examples: updateCampaignBudget (change daily budget), updateBid / bulkUpdateBids (change CPC bids), createCampaign (creates campaigns which set budget and bidding behavior), pauseCampaign/enableCampaign/removeCampaign (start/stop spend), and other write ops that return changeIds and are logged. updateCampaignBudget is an explicit "manage ad spend budgets" API (with guardrails), which meets the definition of Direct Financial Execution.

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 29, 2026, 02:27 PM
Issues
2
Security Audit — snyk — ads