Back to skill

Security audit

TikTok Shop 商品全链路调研:搜索、选品与商品详情【Gecho 官方】

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed TikTok Shop research helper that routes read-only product searches/details through Gecho's MCP tooling, with no hidden destructive or unrelated behavior found.

Before installing, confirm you are comfortable using Gecho Bridge, its Chrome extension, and a logged-in TikTok Shop browser session. Treat returned product data and any saved JSON as marketplace research data from your authenticated session.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file contains user-facing instructions, examples, workflow text, and required responses exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is in scope unless the locale constraint is explicitly documented and justified, which is not present here.

Static analysis

No suspicious patterns detected.