adkit
Warn
Audited by Snyk on Apr 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly an interface to Meta and Google Ads with commands to create, update, and publish campaigns/ad groups/ads and to set budgets (e.g.,
--budget-daily 10, create/update/delete entities,adkit manage drafts publish <id>). It requires authenticating ad accounts and includes escape hatches (--data <json>,--platform-overrides <json>) that let the agent send raw API request bodies or platform-specific fields. These are specific, purpose-built controls to start/modify ad campaigns and budgets (i.e., to execute ad spend), not generic tooling. Therefore it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata