Back to skill

Security audit

Douyin Short Video Factory

Security checks across malware telemetry and agentic risk

Overview

This appears to be a Douyin-focused helper skill with one scope-quality concern, but no evidence of hidden execution, credential access, persistence, or malicious behavior.

Install only if you want an assistant to help with Douyin-specific creation, parsing, or download-link tasks. Be careful to confirm intent before using download links, and respect Douyin terms, copyright, and creator permissions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrase "douyin" is extremely broad and can match many unrelated user requests about the platform, causing the skill to activate unexpectedly. In this skill's context, unintended activation is more concerning because it includes parsing and download-link functionality for third-party video content, which could steer users into actions they did not explicitly request.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.