Back to skill

Security audit

Tiktok Auto Reply

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly aimed at automating TikTok replies, but it handles account credentials and promised dry-run behavior too loosely for public posting automation.

Review before installing. Use a dedicated low-privilege TikTok app or test account, avoid storing real tokens in the project directory, add config.json to .gitignore, and do not rely on dryRun as a safety control unless the code is fixed to enforce it. Treat watch mode as live automation and monitor account activity closely.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Note
Location
package.json:19
Finding

Unused Mutable Dependency Introduces Avoidable Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:35
Finding

TikTok API Credentials Are Stored in a Plaintext Project Configuration File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README forces a single language/locale experience for all users through its natural-language instructions and warnings. Under the stated policy, this is a violation unless the skill offers language choice or clearly documents a justified region-specific limitation, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill name, warnings, setup, usage instructions, and disclaimer are all written in Chinese, with no indication that users may choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The config specifies Chinese keywords and Chinese reply templates, which implies the skill is constrained to a specific language/locale. There is no accompanying natural-language indication that the user can choose the language or that the locale restriction is intentional and documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file’s user-facing description and operational messages are entirely in Chinese, beginning with a Chinese-only skill title. Under the policy, language restrictions should offer user opt-in or be clearly documented as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The program advertises dryRun=true as a mode that will not actually send replies, but the control flow does not enforce that guarantee before invoking replyComment. In a real implementation where replyComment performs live API calls, operators may unintentionally automate account actions despite believing they are in safe test mode, causing unauthorized posting, rate-limit issues, or account sanctions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description and display name are written only in Chinese ("TikTok 热门视频自动回复技能" / "TikTok 自动回复"), which imposes a specific language in user-facing metadata without offering an alternative or opt-in. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
83% confidence
Finding

The dependency uses a semver range (^2.6.9) rather than an exact pinned version, which can lead to non-reproducible installs and unexpected adoption of changed transitive code. In a skill context that may process social-media data or perform automated actions, this weakens supply-chain control and makes dependency risk harder to assess.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
"node": ">=18.0.0"
  },
  "dependencies": {
    "node-fetch": "^2.6.9"
  },
  "clawhub": {
    "slug": "tiktok-auto-reply",

Unverifiable Dependency: node-fetch has 3 known advisory(ies) (CVE-2022-0235 (node-fetch forwards secure headers to untrusted sites); CVE-2022-2596 (node-fetch Inefficient Regular Expression Complexity ); CVE-2020-15168 (The `size` option isn't honored after following a redirect in node-fetch)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The manifest references node-fetch with a non-exact version while known advisories exist in the 2.x line, so the actual installed package may be vulnerable depending on resolution. Even though package.json alone does not prove exploitation, leaving an advisory-affected dependency range unresolved creates avoidable supply-chain and runtime risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.