Back to skill

Security audit

ExportDou 抖音评论导出

Security checks across malware telemetry and agentic risk

Overview

This skill coherently helps export and preview public Douyin comments through the ExportDou CLI, with clear limits around public content, credentials, credits, and local downloads.

Install only if you are comfortable using ExportDou and npx to process public Douyin links. Expect browser-based ExportDou login, possible credit use for exports, local output files, and public comment data that may still contain personal information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The description says to use the skill when users ask to “查看、总结或分析抖音评论、评论回复、用户反馈,” which includes broad phrases like summarizing or analyzing feedback without clear trigger boundaries. Although Douyin is mentioned, the invocation guidance lacks explicit exclusions or negative examples, making activation scope ambiguous for common analysis requests involving user feedback.

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
The manifest description specifies activation conditions entirely in Chinese and includes Chinese-only examples such as “全部,” without stating that the skill is intentionally limited to Chinese-language use or offering multilingual alternatives. This can create a language/locale policy issue because the skill appears to privilege one language without explicit user opt-in or documented justification.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.