Back to skill

Security audit

tiktok-publish-flow

Security checks for vulnerabilities and agentic risk

Overview

This is genuine TikTok automation, but it uses a persistent logged-in browser session and includes unsafe account-login and live-posting practices that should be reviewed before installation.

Install only for an account owner who explicitly wants live TikTok Studio automation. Do not send login QR codes over WhatsApp or other chat channels; perform login locally, restrict access to the persistent profile directory, review/clean screenshot output, and add a dry-run or confirmation gate before publishing or saving edits. Fix the edit script and remove or implement the advertised delete-post capability before relying on it operationally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broader skill covering publish/post, photo posts with music, caption edits, and deletion. This code chunk only implements one subset: editing the caption of an existing TikTok Studio post. It does not publish new content, upload videos/photos, attach music, schedule posts, or delete posts. Additionally, part of the row-finding logic is hardcoded to text starting with '#1HourChallenge', making the implementation narrower than the general description suggests. While caption editing is accurately represented, the overall declared purpose overstates what this supplied code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code substantially matches one subset of the description: posting a TikTok photo with music through TikTok Studio web automation. However, the declared description is broader and presents additional capabilities not present in this code chunk. This script only performs creation of a new single photo post with a selected sound and caption. There is no logic for managing existing posts, editing captions after publication, deleting posts, uploading videos, or scheduling. The mismatch is therefore a description-to-code overclaim of multiple core capabilities, even though the implemented posting behavior itself is on-topic.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The implementation is specifically an upload-and-post flow for a video file on TikTok Studio. It accepts only --video, --caption, and --tag, navigates to the upload page, uploads a file, fills the caption editor, optionally changes privacy/AI-generated toggles, and publishes the post. The declared description is broader and includes several capabilities not present in this code chunk: photo posts with sound/music, editing captions, and deleting posts. While posting TikTok videos via Playwright is accurately represented, the overall declared description overstates what this supplied code chunk actually does, so this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The guidance to capture and send the TikTok login QR code via WhatsApp exposes authentication material in plain-language operational instructions. In this context, the skill automates posting through a persistent logged-in browser profile, so compromise of the QR-based login can directly grant unauthorized access to the TikTok account and downstream control over content publication.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script advertises CLI-controlled post selection via --match, but the DOM search is actually hardcoded to rows whose text starts with '#1HourChallenge'. This creates a deceptive safety boundary: operators may believe they are editing the requested post while the automation is biased toward a fixed campaign/tag, increasing the chance of unauthorized or unintended modification of a live account post.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code accepts --caption but later types CAPTION, an undefined variable, instead of the parsed CLI value. This causes a runtime failure after selecting and opening a live post editor, which can leave the browser in an inconsistent state and makes the script's documented behavior unreliable during sensitive account modifications.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill describes use of environment-controlled paths such as TIKTOK_PROFILE_DIR and TIKTOK_SHOTS_DIR, but does not declare any explicit tool scope or permissions. In an automation skill that handles persistent browser profiles and login state, missing scope declarations increase the chance of overbroad filesystem or environment access and make the skill harder to constrain safely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs operators to capture a TikTok login QR code and send it over WhatsApp without any privacy warning or handling restrictions. Login QR codes are authentication artifacts; transmitting them through external messaging channels increases the risk of account takeover, interception, unintended retention, and disclosure to third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script performs a real caption overwrite and attempts to click a save/post button on a live TikTok account without any explicit confirmation checkpoint immediately before commit. In the context of a TikTok publishing automation skill that operates through a persistent logged-in browser profile, this raises the risk of accidental or mis-targeted content changes becoming public.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The helper saves screenshots of the posting workflow to disk without notice or consent, and those screenshots may capture captions, account information, draft content, music selections, or other sensitive UI state. Because the script takes multiple screenshots throughout the flow, it increases the chance of retaining sensitive material in a predictable local directory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script performs an irreversible publish action by clicking the TikTok 'Post' and optional 'Post now' buttons automatically, with no interactive confirmation, dry-run mode, or explicit user acknowledgment at execution time. In the context of a publishing automation skill, this creates a real risk of accidental or unauthorized posting if the script is invoked with the wrong media, caption, or account session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This script performs an irreversible external side effect—publishing content to a live TikTok account—without any explicit confirmation gate at the point of posting. In the context of an automation skill specifically designed to publish via browser control and persisted login state, accidental invocation, misuse by another workflow, or bad inputs can immediately cause unauthorized or unintended posts on a real account.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The policy applies to natural-language constraints in any file type. Line L10 states that the body of the skill is in Romanian as the working language of the agent that built it, but it does not offer an alternative language or indicate user opt-in for that locale choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The automation logic explicitly targets interface text in English and Romanian (for example, sound picker and privacy labels), which can embed a language assumption into the skill. This creates a locale-policy concern because the user is not offered a language choice and the locale constraint is not documented as intentional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code searches for privacy labels using only Romanian and English text, which reflects an undocumented locale restriction. This may fail for users in other language settings and constitutes a natural-language locale assumption without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The automation searches for Romanian and English UI text labels such as "Toată lumea", "Everyone", and variants of "AI-generated". This embeds locale assumptions into the skill behavior without any user opt-in or configurable language selection, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.