抖音数据分析 SocialDataX 作品详情

Security checks across malware telemetry and agentic risk

Overview

This is a narrow, read-only Douyin detail lookup skill that clearly discloses its SocialDataX API key and npm CLI use.

Install only if you trust SocialDataX and are comfortable using its API key with the disclosed npm CLI/API. The main practical risk is dependency trust: the examples run socialdatax-skills@latest, so future behavior depends on that npm package remaining trustworthy.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal