bee

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it downloads a Douyin video, uploads it to Alibaba OSS, and records metadata in Feishu when the user runs it.

Install only if you intend to send Douyin video content to your configured Alibaba OSS bucket and Feishu Bitable. Use dedicated least-privilege credentials, review the dependent skills, confirm bucket/table visibility and retention, and use --dry-run or skip flags when testing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill description emphasizes convenience but does not prominently warn that user-supplied Douyin content will be uploaded to Alibaba OSS and recorded in Feishu, both third-party services. This creates a privacy and data-governance risk because users may supply links expecting local processing, while the workflow persists content and metadata externally.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal