Back to skill

Security audit

TikTok Shop 商品搜索【Gecho 官方】

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed TikTok Shop product-search helper that routes requests through Gecho Bridge and does not show hidden or destructive behavior.

Before installing, be aware that this skill depends on Gecho Bridge, a Gecho Chrome extension, and an already logged-in TikTok Shop browser session. Use it only if you are comfortable letting that integration read TikTok Shop product pages available in your session, and review the external Gecho package and extension separately if that trust boundary matters to you.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The entire skill description, prescribed prompts, standard responses, and output conventions are written as mandatory Chinese instructions, with no indication that the user may choose another language. This creates a locale/language policy concern because the skill effectively enforces a specific language without documented opt-in or justification as a region-specific-only tool.

Static analysis

No suspicious patterns detected.