Back to skill

Security audit

ExportDou 抖音评论导出

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent helper for exporting public Douyin comments through a third-party CLI, with clear limits around public content, credentials, task handling, and local downloads.

Before installing, confirm you are comfortable using ExportDou as a third-party service for public Douyin comment exports, including its account login, credit usage, and npm CLI execution through npx. Do not provide Douyin cookies or private login state, and use explicit limits for large or reply-inclusive exports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
The manifest description is entirely in Chinese and narrowly frames invocation around Douyin-related requests, which can amount to a language/locale constraint without explicit user opt-in. The file does not state that users may interact in other languages or choose a locale, so this may conflict with language-choice policy expectations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.