Back to skill

Security audit

guaikei-douyin-video-comments-to-sentiment-data

Security checks across malware telemetry and agentic risk

Overview

The skill performs public Douyin data lookups, but its runtime token-error messages contradict its own no-contact/no-marketing claim, so it should be reviewed before install.

Before installing, confirm you are comfortable sending the GUAIKEI_API_TOKEN and requested Douyin search terms or URLs to guaikei.com, and with results being saved locally in logs. The main review issue is that the code can show provider website or WeChat contact text during token/auth errors even though the skill documentation explicitly says runtime output will not do that.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.