TikTok Video Maker

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed LovelyBots video-generation workflow with normal API-key, content-upload, and share-link privacy risks.

Install only if you trust LovelyBots with the scripts and images you provide. Keep LOVELYBOTS_API_KEY secret, confirm credit-consuming generation before using it at scale, and avoid sharing or logging returned video_url and share_url values unless you intend others to access the generated video.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill exposes and repeatedly surfaces `share_url` values without warning that they may grant access to generated user content through a publicly reachable share page. Users or downstream agents may treat these links as innocuous status metadata and disclose them in logs, chats, or external systems, unintentionally leaking private marketing assets or sensitive generated media.

Ssd 3

Medium
Confidence
97% confidence
Finding
The skill explicitly recommends sending `share_url` during in-progress status updates, before the user has confirmed they want the link shared. That creates a direct confidentiality risk because a pre-completion share link may expose user-generated content, work product, or branded assets to unintended recipients through chat history, logs, or other agent integrations.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal