Back to skill

Security audit

tiktok-influencer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed TikTok creator-video collection workflow that uses Gecho and saves local results, with privacy considerations but no evidence of hidden or malicious behavior.

Before installing, be comfortable using Gecho's Chrome extension and MCP server with an active TikTok browser session. Choose a private save directory for results, avoid shared or synced folders if the creator research is sensitive, and review the Gecho extension and MCP package before authorizing them in your environment.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly says it may save the full raw creator-video result set to a local JSON file, but it does not clearly warn users that this file can contain browsing-session-derived data, creator metadata, URLs, timestamps, and other collected content that may persist on disk. In this context, the data is sourced through a live logged-in browser session, so silent local persistence increases privacy and data-handling risk, especially on shared machines or synced workspaces.

Static analysis

No suspicious patterns detected.