performance-marketing-analysis

Fail

Audited by Snyk on Mar 22, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly tells the agent to ask the user for APIFY_TOKEN and ELEVENLABS_API_KEY and to use them to run API calls/scripts (and to accept them if not in env vars), which requires the LLM to receive and potentially embed secret values verbatim—an exfiltration risk.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly instructs the agent to use Apify (calling the actor curious_coder/facebook-ads-library-scraper) to fetch competitor ads from Facebook/Instagram and to use those scraped, third‑party ad contents to inform campaign strategy and generate copy, which is untrusted public content the agent will read and act on.

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
HIGH
Analyzed
Mar 22, 2026, 10:50 PM
Issues
2
Security Audit — snyk — performance-marketing-analysis