Scanned skills

linkfox-ai/linkfox-skills linkfox-amazon-ads-report

Checked the catalogued skill at linkfox-amazon-ads-report.

SkillTrust corpus scan 15 September 2026 v0.10.0 via skillsh Verify on GitHub
D AI-triaged 48
D Security

D; retained sample includes a high finding · SD-007 · what this rule accepts as a false positive →

D Permissions

D; retained sample includes a high finding · SD-003 · what this rule accepts as a false positive →

A Transparency

A set by no findings on this axis

showing 10 of 48
permission_hygienehigh SD-003
SKILL.md
securitymedium SD-008
references/report-types/sb/sbCampaigns.md
securityhigh SD-007
references/report-types/sb/sbCampaigns.md
securityhigh SD-007
references/report-types/sb/sbPromptAdExtension.md
securitymedium SD-008
references/report-types/sb/sbSearchTerm.md
securityhigh SD-007
references/report-types/sb/sbSearchTerm.md
securityhigh SD-007
references/report-types/sb/sbTargeting.md
securityhigh SD-007
references/report-types/sd/sdAdGroup.md
securityhigh SD-007
references/report-types/sd/sdAdvertisedProduct.md
securityhigh SD-007
references/report-types/sd/sdCampaigns.md
12 suppressed by AI triage
permission_hygienehigh SD-003 benign_example
references/api.md

Documentation example showing a placeholder path, not actual code that performs path traversal.

transparencymedium SD-007 benign_example
references/api.md

Sample curl command in documentation, not an executed outbound request.

securitycritical SD-013 benign_example
references/onboarding.md

The snippet is part of onboarding documentation, not executed code, so no real persistence is established.

securitycritical SD-013 benign_example
references/onboarding.md

The snippet is documentation for adding an env variable to .bashrc, not an active persistence mechanism.

securitymedium SD-008 benign_example
references/report-types/sb/sbAdGroup.md

The listed strings are plain metric names in documentation, not a base64 encoded payload.

securityhigh SD-007 benign_example
references/report-types/sb/sbAdGroup.md

The curl example is illustrative documentation of API usage, not an executed malicious call.

securitymedium SD-008 benign_example
references/report-types/sb/sbAds.md

The matched content is a list of table headers, not an encoded payload.

securityhigh SD-007 benign_example
references/report-types/sb/sbAds.md

The curl command is part of example documentation, not an executed or malicious request.

securitymedium SD-008 benign_example
references/report-types/sb/sbCampaignPlacement.md

The string matched is a field name, not a base64-encoded payload.

securityhigh SD-007 benign_example
references/report-types/sb/sbCampaignPlacement.md

The curl snippet is sample documentation, not an executed network call.

securitymedium SD-008 benign_example
references/report-types/sb/sbPurchasedProduct.md

The base64-like string is part of documentation examples, not an obfuscated malicious payload.

securityhigh SD-007 benign_example
references/report-types/sb/sbPurchasedProduct.md

The curl command is a sample usage in documentation, not an actual outbound attack.