Back to skill

Security audit

TikTok

Security checks across malware telemetry and agentic risk

Overview

This TikTok planning skill stores creator notes and analytics locally, with no evidence of network access, account login, posting, scraping, or hidden automation.

Install this only if you want a local TikTok/short-form content workspace. It can save profile strategy, drafts, hooks, captions, notes, and manually entered performance metrics on your machine until you delete them; avoid storing information there that you would not want in local plaintext files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill explicitly describes local file storage and lists scripts that create, update, read, and write memory files, but no permissions are declared in the skill metadata. That mismatch is a real security issue because it hides capability from reviewers and any permission-gating system, increasing the chance of unintended file access or writes without clear user awareness.

Vague Triggers

Medium
Confidence
74% confidence
Finding
The invocation description is broad enough to activate on generic short-form content requests such as hooks, scripts, retention, or virality, even when the user may not want this specific skill. This is a genuine security/control concern because over-broad triggering can cause unintended access to local memory files and unexpected behavior outside clear TikTok-specific intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.