Back to skill

Security audit

TikTok 选品、趋势、竞品与内容洞察【Gecho 官方】

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed TikTok research workflow that depends on Gecho’s MCP bridge and Chrome extension, with no artifact evidence of hidden or destructive behavior.

Before installing, understand that this workflow relies on a third-party Gecho Chrome extension and MCP bridge using your logged-in TikTok browser session. Use it only if you trust Gecho with the TikTok data visible in that session, and review the external package/extension permissions separately.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The text specifies that the agent may translate the standard response to match the user's language, implying the default template and surrounding skill behavior are anchored to Chinese unless adaptation occurs. This creates a locale/language policy concern because the skill does not clearly offer user opt-in or a neutral language-choice mechanism.

Static analysis

No suspicious patterns detected.