Back to skill

Security audit

TikTok Shop 商品详情【Gecho 官方】

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed TikTok Shop product-detail helper that routes requests to Gecho Bridge and does not show hidden or destructive behavior.

Before installing, confirm you trust Gecho Bridge and the Chrome extension, because the workflow relies on your logged-in browser session to access TikTok Shop pages. Use it only for product-detail collection, review any saved output location, and do not enter passwords or payment information into the skill itself.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The file consistently mandates Chinese-language interaction in its natural-language content, and there is no indication that users may choose another language. The policy only permits locale or language constraints when the skill offers opt-in or clearly documents a justified region-specific language requirement, which is not present here.

Static analysis

No suspicious patterns detected.