paid-ads

Warn

Audited by Snyk on Feb 27, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly about managing paid advertising campaigns and repeatedly references budgets (asking for monthly/weekly budget, "Budget set correctly" checklist, guidance to increase budgets 20–30%, budget allocation and pacing, and spend vs. budget pacing in reporting). It also states the agent has "direct access to ad platform accounts" and points to platform integration docs (e.g., google-ads.md) in the tools registry — implying the agent can act in ad accounts. Managing ad spend (updating campaign budgets/bids) is a specific financial operation (affects money flow). Even though no raw SDK call is shown inline, the skill is specifically designed to operate and change ad budgets via ad-platform integrations, which falls under Direct Financial Execution (managing ad spend budgets). Therefore it should be flagged.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 27, 2026, 09:20 PM