adspy-analytics-intelligence

Fail

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The installation section for Windows provides a command that uses Invoke-RestMethod (irm) to fetch a script and pipe it directly into Invoke-Expression (iex). This pattern (irm ... | iex) allows for immediate execution of remote code from the dustfinderfactory GitHub account without any verification or user review.
  • [EXTERNAL_DOWNLOADS]: The skill directs users to clone a repository from NebulaFormCorridor on GitHub. This repository and user account are unverified, posing a supply chain risk if the repository contains malicious scripts or binaries.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and display untrusted data from external advertising networks (e.g., ad headlines, creative text, and landing pages). There is a risk of indirect prompt injection where instructions embedded in ad content could influence the agent's behavior. Evidence: The ingestion occurs via search_ads and track_advertiser functions in the Python library; boundary markers are not documented to separate data from instructions; the skill has significant capabilities including CLI execution (adspy) and file export; and no sanitization of the external content is described.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — adspy-analytics-intelligence