Back to skill

Security audit

TikTok Viral Slideshow Automation

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it can publish TikTok content on a schedule and run user-pasted generation commands without enough safety guardrails.

Install only if you are comfortable with an agent that can spend image-generation credits and publish through AutomateClips. Avoid Option D unless you fully trust and understand the command, use a dedicated project directory and minimal environment variables, and prefer manual review or dry-run behavior before enabling any recurring schedule.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:127
Finding

Unpinned Third-Party Dependencies Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
\ openai== \ google-genai== ``` 2. Maintain a lock file containing exact transitive dependency versions. 3. Require package hashes with `pip install --require-hashes`. 4. Install packages inside a dedicated virtual environment rather than the user's global Python environment. 5. Review release notes and package provenance before updating pinned versions. 6. Use trusted package indexes and disable unexpected supplemental indexes. 7. Run dependency vulnerability and integrity scans in the release process. 8. Expose only the API credential needed by the selected image provider rather than placing all provider credentials in the same runtime environment. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:243
Finding

Unvalidated Custom Generation Commands May Permit Arbitrary Shell Execution

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The scheduled automation section instructs another skill to autonomously fetch analytics, generate content, upload posts, and write to a local tracking file on a recurring schedule, but it does not require an explicit confirmation step or prominently warn the user that future runs will perform publishing and file modifications without review. In a marketing workflow, that creates a real risk of unintended posting, quota/cost consumption, and silent local state changes if the schedule is enabled too casually or later forgotten.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.