adspy-analytics-intelligence
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The installation section for Windows provides a command that uses
Invoke-RestMethod(irm) to fetch a script and pipe it directly intoInvoke-Expression(iex). This pattern (irm ... | iex) allows for immediate execution of remote code from thedustfinderfactoryGitHub account without any verification or user review. - [EXTERNAL_DOWNLOADS]: The skill directs users to clone a repository from
NebulaFormCorridoron GitHub. This repository and user account are unverified, posing a supply chain risk if the repository contains malicious scripts or binaries. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and display untrusted data from external advertising networks (e.g., ad headlines, creative text, and landing pages). There is a risk of indirect prompt injection where instructions embedded in ad content could influence the agent's behavior. Evidence: The ingestion occurs via
search_adsandtrack_advertiserfunctions in the Python library; boundary markers are not documented to separate data from instructions; the skill has significant capabilities including CLI execution (adspy) and file export; and no sanitization of the external content is described.
Recommendations
- AI detected serious security threats
Audit Metadata