Back to skill

Security audit

DeepSop TK工作台

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it helps generate and schedule TikTok videos through DeepSOP, with real account impact that users should review before use.

Install only if you intend the agent to use your DeepSOP API key to manage TikTok video generation, posting, scheduling, and analytics. Before any task submission, verify the selected TikTok account, generated prompt, privacy level, posting schedule, and any package or K-coin purchase choice, because those actions can affect public accounts and account balance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README promotes automated TikTok posting and later analytics collection, but does not clearly warn users that the skill can perform account-impacting actions on their behalf or that post-publication metrics and linked account data may be processed. In a skill that generates content and publishes to a third-party social account, missing consent, visibility, and privacy warnings increases the risk of unintended posting, brand damage, or unauthorized handling of account-linked data.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:32