Back to skill

Security audit

Apify TikTok Comment Scraper

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it relies on a user Apify token and repeatedly places that token in request URLs, which is a credential-handling risk users should review before installing.

Review this before installing if your Apify token has broad permissions or billing access. Use a narrow, revocable token where possible, avoid copying examples that put tokens in URLs, prefer Authorization headers, and assume TikTok URLs, scraping settings, and collected comment data will be processed by Apify.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:46
Finding

Apify API Token Exposed in URL Query Strings

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
|-----------|------|----------|-------------|
| `videoUrls` | array of strings | **Yes** | TikTok post URLs (video, photo, or short links). Max 50, must be unique. |
| `maxCommentsPerVideo` | integer | No | Max top-level comments per post. Default: 100. Min: 1, Max: 5000 |
| `includeReplies` | boolean | No | Collect threaded replies. Default: true |
| `maxRepliesPerComment` | integer | No | Max replies per comment. Default: 50. Min: 1, Max: 500 |

## Complete Example (Python)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are somewhat broad because they include generic requests like analyzing TikTok engagement, which could cause the skill to activate in contexts broader than strict comment scraping. This is not directly exploitable like code execution, but it can lead to unintended invocation and surprise data transfer to the external Apify service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user-supplied TikTok URLs and retrieves comment data through a third-party service, but the description does not warn users that their inputs and resulting data are transmitted to Apify. This creates a transparency and privacy risk because users may not realize external processing occurs.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The presence of the Apify API base URL indicates the skill is designed to communicate with an external service. By itself this line is only an endpoint definition, but in context it supports real outbound data flow and therefore contributes to the external transmission concern.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
import requests, os, time

TOKEN = os.environ["APIFY_API_TOKEN"]
BASE = "https://api.apify.com/v2"

# Step 1: Start the run
response = requests.post(

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This code explicitly transmits user-provided TikTok URLs and scraping parameters to the Apify API, which is a third-party external service. The transmission itself is expected for the skill's function, but it is still a real data egress point with privacy and data-handling implications.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
BASE = "https://api.apify.com/v2"

# Step 1: Start the run
response = requests.post(
    f"{BASE}/acts/futurizerush~tiktok-comment-scraper/runs?token={TOKEN}",
    json={
        "videoUrls": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This example also sends user-specified TikTok URLs to Apify, including potentially multiple videos in one request, increasing the volume of externally shared data. In context this is intended functionality, but it remains a genuine external transmission risk.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

Multiple videos

python
requests.post(
    f"{BASE}/acts/futurizerush~tiktok-comment-scraper/runs?token={TOKEN}",
    json={
        "videoUrls": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The bash example transmits data to Apify and includes the API token directly in the request URL, which can increase exposure through shell history, logs, proxies, or process inspection. Although common in simple examples, this is a security weakness in addition to the underlying third-party transmission.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

bash
# Step 1: Start the run
RUN_RESPONSE=$(curl -s -X POST \
  "https://api.apify.com/v2/acts/futurizerush~tiktok-comment-scraper/runs?token=$APIFY_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"videoUrls": ["https://www.tiktok.com/@bellapoarch/video/6862153058223197445"], "maxCommentsPerVideo": 20, "includeReplies": true}')

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This endpoint usage shows a POST request to Apify with the API token in the URL, combining external transmission with unnecessary credential exposure risk. If logs or monitoring capture request URLs, the token may be disclosed.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

bash
# Step 1: Start the run
RUN_RESPONSE=$(curl -s -X POST \
  "https://api.apify.com/v2/acts/futurizerush~tiktok-comment-scraper/runs?token=$APIFY_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"videoUrls": ["https://www.tiktok.com/@bellapoarch/video/6862153058223197445"], "maxCommentsPerVideo": 20, "includeReplies": true}')

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

Polling the external Apify run-status endpoint is another outbound call to the third-party service. It does not add much new data exposure beyond the initial submission, but it confirms ongoing interaction with the external processor.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
# Step 2: Poll until done
while true; do
  STATUS=$(curl -s "https://api.apify.com/v2/actor-runs/$RUN_ID?token=$APIFY_API_TOKEN" \
    | jq -r '.data.status')
  [ "$STATUS" = "SUCCEEDED" ] && break
  [ "$STATUS" = "FAILED" ] || [ "$STATUS" = "ABORTED" ] && echo "Failed: $STATUS" && exit 1

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

Fetching dataset items from Apify returns scraped TikTok comments and replies from a third-party system, which means retrieved content flows through and is exposed to that external platform. This is integral to the skill, but it still creates privacy, compliance, and data residency concerns.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

done

Step 3: Fetch results

curl -s "https://api.apify.com/v2/datasets/$DATASET_ID/items?token=$APIFY_API_TOKEN" | jq '.'

text

## Output Format

Static analysis

No suspicious patterns detected.