Back to skill

Security audit

TikTok 达人视频采集、数据分析与内容研究【Gecho官方】

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly scoped TikTok creator-research helper that uses the disclosed Gecho MCP and browser extension workflow, with expected local saving of collected public metadata.

Install this only if you are comfortable using Gecho Bridge with a logged-in TikTok browser session and saving creator research results locally. On shared or managed machines, provide an explicit save_dir or avoid saving data you do not want retained in the workspace.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
86% confidence
Finding
The skill explicitly states that collected TikTok creator data may be saved as a local JSON file, but it does not clearly warn the user up front about when a file write will occur, what default directory may be used, or that scraped data will persist on disk. This can surprise users and create unintended local data retention, especially on shared machines or managed environments where social media research data may be sensitive or policy-restricted.

Static analysis

No suspicious patterns detected.