Douyin Creator Marketplace (Xingtu) Conversion Resources API

Security checks across malware telemetry and agentic risk

Overview

This is a focused API wrapper for one JustOneAPI Douyin/Xingtu endpoint, with the main caution that its token is sent as a URL query parameter.

Install only if you are comfortable using a JustOneAPI token for this specific Douyin/Xingtu endpoint. Prefer a limited-scope or easily rotated token if available, avoid sharing command lines or logs that include request URLs, and rotate the token if you suspect it was captured in logs or telemetry.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The API requires a sensitive authentication token in the query string, which is routinely exposed in logs, browser history, analytics systems, reverse proxies, and referrer headers. In an agent/tooling context, this is more dangerous because orchestration layers often record full URLs, making accidental credential disclosure more likely even when transport is encrypted.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The documentation instructs callers to supply a user authentication token in a query parameter but provides no warning about secure handling, storage, logging, or leakage risks. Query-string credentials are especially sensitive because they are commonly exposed in logs, browser history, analytics, proxies, and referrer headers, making accidental disclosure more likely in an agent/tooling context.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal