Back to skill

Security audit

TikTok Video Detail and Comments by Gecho

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed TikTok video-reading workflow that uses Gecho’s MCP tool and browser extension, with no evidence of hidden, destructive, or unrelated behavior.

Before installing, confirm you are comfortable using a third-party Gecho MCP package and Chrome extension with a logged-in TikTok browser session, and review where raw JSON results will be saved if the collected data may be sensitive.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Missing User Warnings

Low
Confidence
84% confidence
Finding
The markdown states that the skill saves raw results to a local JSON file when a usable directory is available. Although this behavior is documented, it is presented as a feature rather than a caution, and there is no explicit warning about local persistence of potentially sensitive collected data or guidance to opt out unless `save_dir` is omitted.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Content
Join the [WeCom group](https://github.com/gecho-ai/gecho-bridge/blob/main/qywx.jpg), visit [Discord](https://discord.gg/RFDVZMR6Tn), or scan the [1:1 support QR code](https://github.com/gecho-ai/gecho-bridge/blob/main/wx.jpg) for personal help.

## Output guidelines

For successful video-detail collection:
Confidence
85% confidence
Finding
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Static analysis

No suspicious patterns detected.