Back to skill

Security audit

TikTok 爆款视频搜索、数据采集与达人发现【Gecho 官方】

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed TikTok search helper that uses Gecho’s browser-session MCP workflow and local result files for its stated purpose.

Install only if you are comfortable connecting Gecho to a logged-in TikTok browser session. Expect complete search results to be saved locally as JSON, usually in the workspace or a default Gecho directory, and delete or protect those files if the searches contain sensitive business, research, or personal context. Review the external Gecho bridge and Chrome extension separately because this skill delegates runtime behavior to them.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill explicitly instructs collection and local saving of complete TikTok search results as JSON, but does not clearly warn users that scraped metadata may be stored on disk, persist after the session, and potentially include sensitive or regulated data depending on usage. In a browser-session-backed social media scraping workflow, unclear disclosure around local retention increases privacy, compliance, and accidental exposure risk.

Static analysis

No suspicious patterns detected.