Back to skill

Security audit

抖音KOL对标账号

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Douyin KOL search helper that calls an external AI Skills API, with no evidence of hidden persistence, local data harvesting, destructive behavior, or deceptive actions.

Install only if you are comfortable using an external AI Skills service for Douyin creator research. Keep the API key in environment variables, use a trusted AISKILLS_BASE_URL, and avoid sending confidential strategy, private personal data, or regulated information as search terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Low
Confidence
80% confidence
Finding
The documentation tells users to supply an API key and send request data to a third-party service, but it provides no warning about secure credential handling, logging exposure, or the privacy implications of transmitting potentially sensitive business inputs. In this skill's context, users may submit competitive research terms, brand strategy, or creator-selection criteria, so omitted disclosure can lead to inadvertent data leakage or unsafe operational practices.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt and display text are broad enough to match ordinary user requests about Douyin KOLs, which can cause the skill to be invoked implicitly when the user did not clearly opt into this specific capability. That creates prompt-routing risk: unrelated or sensitive user queries about creators, competitors, or partnerships may be steered into this skill unexpectedly, potentially exposing user context or producing actions/results outside user intent.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The manifest exposes a Chinese-language skill without indicating language selection or confirming that the user wants Chinese responses. This can lead to accidental invocation for users in other languages, reducing transparency and increasing the chance of misunderstanding what the skill will do or return.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt uses a very broad invocation phrase ('Use $douyin-kol-search to help with ...') without defining clear activation boundaries or user-intent constraints. This can cause the skill to be invoked in loosely related contexts, increasing the risk of unintended tool use, data exposure to the skill, or irrelevant/autonomous behavior that the user did not explicitly request.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.