Back to skill

Security audit

TikTok Shop Spy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent TikTok Shop research guide that discloses its ClawLink plugin dependency, paid public-data calls, and read-only TikTok Shop use.

Before installing, understand that this depends on the ClawLink plugin, one-time account/device pairing, and paid ClawLink credit for data calls. Treat issue reports as information sent to ClawLink support and avoid including sensitive prompts, private account data, or unnecessary identifiers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill repeatedly frames itself as read-only and limited to public-data access, but later instructs the agent to use an issue-reporting tool that transmits information to ClawLink. That mismatch can cause users or downstream agents to disclose prompts, tool arguments, error details, or other context to a third party without clear consent, violating the stated trust boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The instruction says to use the skill whenever the user wants TikTok Shop products, stores, reviews or creator showcases, which is a broad activation condition rather than a specific trigger set. Although the document gives examples, it does not clearly define exclusions beyond private accounts and write actions, so the skill may be invoked for loosely related requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The note states that US results are the most reliable and other regions may be incomplete, which introduces a locale preference affecting behavior. The file does not pair this with a user choice or explicit opt-in for locale handling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The issue-reporting action is outside the core TikTok Shop research scope and introduces an outbound data-sharing path unrelated to the advertised functionality. While not inherently malicious, extra capabilities increase attack surface and can lead to unanticipated disclosure of conversation or operational metadata.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.