Security audit
guaikei-douyin-feed-processing-pipeline
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed command-line tool for retrieving public Douyin data through a third-party API using a user-provided token.
Before installing, confirm you are comfortable using guaikei.com as a third-party service and sending it your API token plus the Douyin keywords or public links you ask the skill to process. The tool stores fetched results locally in logs for some commands, so avoid using it for data you would not want retained in the skill directory.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
