Back to skill

Security audit

抖音内容研究

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only Douyin research skill that uses SocialDataX with an API key and does not ask to log in, post, or change accounts.

Install only if you are comfortable running the SocialDataX npm CLI and sending Douyin search terms, pagination tokens, and your SocialDataX API key to the hosted SocialDataX service. For stricter supply-chain control, pin or review the npm package version instead of relying on @latest.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.