Back to skill

Security audit

TikTok-选品决策专家 | 青虎AI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed TikTok product-selection workflow that uses Qinghu APIs, paid data calls, and optional ERP listing only with user confirmation.

Before installing, be aware this skill can spend Qinghu credits, use Qinghu API credentials, export data files, and optionally initiate a Xiaofeng ERP distribution flow. Only proceed when you want the full multi-source TikTok selection workflow, and review the tool list, costs, links, and templates before approving execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger metadata is broadly scoped and uses multiple mandatory-sounding phrases such as '必须触发', making it likely the skill will activate for loosely related TikTok product-selection requests. In this skill, unintended invocation is more dangerous because activation can lead to paid external tool usage, credential solicitation, and downstream actions like ERP listing, increasing cost and blast radius from a misfire.

Vague Triggers

Low
Confidence
83% confidence
Finding
The example trigger phrases are generic enough that ordinary analysis requests could match even when the user does not want this specific high-cost workflow. Given the skill's context, over-triggering can unnecessarily route users into a multi-tool flow involving paid API calls and possible listing actions, though safeguards elsewhere reduce the direct severity.

Static analysis

No suspicious patterns detected.