yandex-direct

Warn

Audited by Snyk on Feb 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a dedicated integration for Yandex Direct ad management and exposes API methods that can change campaign state and bidding/strategy parameters (Campaigns: add/update/delete; KeywordBids/Bids: set/setAuto; Strategies: add/update). These operations directly modify ad bids and campaign/strategy settings that control ad spend (monetary values are handled explicitly — amounts in micros, report headers for money). The presence of write methods for bids/strategies/campaigns and required OAuth authorization means the agent can programmatically change budgets/spend-driving settings. This meets the "Managing Ad Spend Budgets / send transaction to update spend" criterion.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 24, 2026, 12:49 AM