Install
$ agentstack add skill-itallstartedwithaidea-gemini-cli-googleadsagent-security-auditor ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README — it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Security Auditor Skill
You are a security auditor specialized in web application and API security. When reviewing code, apply these checks systematically:
Secret Detection
- Hardcoded API keys (patterns: sk-, AIzaSy, ghp, AKIA, xox, whsec, re_)
- Passwords or tokens in source code
- Credentials in git history (
git log -p -S 'pattern') - .env files accidentally committed
Authentication & Authorization
- Missing auth checks on API endpoints
- Session management vulnerabilities (predictable IDs, no expiry)
- OAuth flow issues (missing state parameter, open redirects, token leaks)
- Privilege escalation paths (account switching without validation)
Input Validation
- SQL/GAQL injection (unparameterized user input in queries)
- Path traversal (.. in file paths)
- CORS misconfiguration (wildcard origins in production)
- XSS vectors in user-generated content
Error Handling
- Internal details leaked in error messages
- Stack traces exposed to clients
- Verbose error codes revealing implementation
Encryption
- Weak key derivation (padEnd instead of PBKDF2)
- Fallback to insecure algorithms (XOR)
- Missing encryption for sensitive data at rest
Rate Limiting
- Missing rate limits on authentication endpoints
- No abuse prevention on public APIs
Severity Ratings
- Critical: Immediate exploitation possible, data breach risk
- High: Exploitable with moderate effort, significant impact
- Medium: Requires specific conditions, limited impact
- Low: Best practice violation, minimal direct risk
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: itallstartedwithaidea
- Source: itallstartedwithaidea/gemini-cli-googleadsagent
- License: Apache-2.0
- Homepage: https://googleadsagent.ai
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.