Back to skill

Security audit

Douyin

Security checks across malware telemetry and agentic risk

Overview

This is a content-writing skill for improving Douyin short-video scripts and does not request code execution, credentials, files, or account access.

Install this if you want Douyin-specific script feedback. Use it intentionally for Douyin-oriented script work, and treat traffic or retention advice as creative guidance rather than a guarantee of reach or platform performance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list contains broad phrases like '完播率', '流量拆解', and 'douyin retention' that can appear in ordinary discussion, which increases the chance the skill activates when the user did not explicitly request this capability. Unintended activation can cause prompt-routing errors, irrelevant transformations, or inappropriate handling of user content in mixed-agent environments.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal