Back to skill

Security audit

tiktok-insight

Security checks across malware telemetry and agentic risk

Overview

This skill has a coherent TikTok research purpose, but it connects AI tools to a logged-in browser session and installs a broader background bridge than the skill name implies.

Review the Gecho extension and MCP bridge before installing. Use this only with a TikTok account/session you are comfortable exposing to a browser-automation research workflow, choose a save directory intentionally, and disable the extension or log out when you no longer want the bridge to access session-visible data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill requires a logged-in TikTok browser session and a Chrome extension that bridges browser data into the MCP workflow, but the user-facing warning does not clearly and explicitly disclose that running jobs may access and transmit data from that authenticated session. This weakens informed consent and can lead users to expose account-session-derived content, engagement data, or other visible browser data without understanding the privacy implications.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.