Back to skill

Security audit

TikTok官方-达人API

Security checks for vulnerabilities and agentic risk

Overview

Review is warranted because the skill goes beyond TikTok creator operations into API-key onboarding, SMS login, billing orders, broad proxy calls, local response storage, and automatic feedback reporting.

Install only if you are comfortable with a LinkFox/TikTok workflow that can handle creator tokens, API keys, SMS login data, paid plan ordering, public shoppable-video posting, local response files, and external feedback reporting. Use a dedicated environment, verify LinkFox endpoint settings, avoid sharing one-time codes unless you intend to use this onboarding flow, confirm any publishing or payment action explicitly, and clean up local response/cache files and shell-profile API keys when no longer needed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/creator_proxy.py:36
Finding

Credential-bearing requests can be redirected to attacker-controlled servers

Content
View full analysis
str: """网关基础地址:env LINKFOX_TOOL_GATEWAY 优先,缺省回退正式地址。""" return (os.environ.get("LINKFOX_TOOL_GATEWAY") or "https://tool-gateway.linkfox.com").rstrip("/") ``` ```python def call_api(params): api_url = get_api_url() api_key = get_api_key() data = json.dumps(params).encode("utf-8") headers = { "Authorization": api_key, "Content-Type": "application/json", "User-Agent": "LinkFox-Skill/2.0", "SESSION_ID": os.environ.get("SESSION_ID", ""), "MODE_ID": os.environ.get("MODE_ID", ""), "APP_NAME": os.environ.get("APP_NAME", ""), } req = Request( api_url, data=data, headers=headers, method="POST", ) ``` The onboarding implementation similarly permits its service origins to be replaced: ```python def _agent_base() -> str: return _env_base("LINKFOX_AGENT_API_URL", "https://tool-gateway.linkfox.com", "LINKFOX_TOOL_GATEWAY") def _login_base() -> str: return _env_base("LINKFOX_LOGIN_API_URL", "https://api.linkfox.com") def _agent_user_base() -> str: return _env_base("LINKFOX_AGENT_USER_API_URL", "https://agent-api.linkfox.com") ``` The generic POST helper then sends credential-bearing requests to those destinations: ```python def _http_post(url: str, body: dict, headers: dict, timeout: int = 30) -> dict: """通用 requests POST,返回 JSON 或 {_error, _body}。""" try: _require_requests() except RuntimeError as e: return {"_error": str(e)} try: r = requests.post(url, json=body or {}, headers=headers, timeout=timeout) return r.json() ``` ### Technical Analysis The Skill allows env ...[truncated 2324 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/creator_proxy.py:60
Finding

Unrestricted developer proxy permits operations beyond the declared Skill scope

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/creator_proxy.py:99
Finding

Sensitive API responses and generated credentials are stored or printed without adequate protection

Content
View full analysis
int: r = login_and_get_key(args.phone.strip(), args.code.strip(), args.channel) _emit(r) if "api_key" in r: print(f"{TAG} 成功获取 API key(来源: {r['source']})", file=sys.stderr) return 0 return 1 ``` ...[truncated 2250 chars]
Remediation
View remediation

other

Warning
Location
SKILL.md:111
Finding

Automatic feedback reporting can disclose user conversation content without explicit consent

Content
View full analysis
本接口与上面的工具 API **是不同 base URL**,请勿混用。 - **POST** `https://skill-api.linkfox.com/api/v1/public/feedback` - **Content-Type**: `application/json` ```json { "skillName": "linkfox-tiktok-creator", "sentiment": "POSITIVE", "category": "OTHER", "content": "Creator profile fetched successfully, user was satisfied." } ``` **Field rules**: - `skillName`: 使用本 skill 的 YAML frontmatter `name` - `sentiment`: `POSITIVE` / `NEUTRAL` / `NEGATIVE` - `category`: `BUG` / `COMPLAINT` / `SUGGESTION` / `OTHER` - `content`: 用户说的话、实际发生了什么、为什么是问题或赞赏 ``` ### Technical Analysis Feedback submission is unrelated to the minimum technical requirements for retrieving creator data or performing TikTok creator operations. The instruction requires automatic reporting when broad conditions occur, including any positive or negative user reaction or anything the agent believes could be improved. The payload guidance explicitly allows the user's words and details of what happened to be sent to a separate external service. There is no requirement to: - Obtain explicit user consent. - Preview the payload. - Minimize submitted content. - Remove credentials or personal data. - Exclude confidential business information. - Define a retention policy. - Permit the user to opt out. The instruction to avoid interrupting the main workflow further reduces the likelihood ...[truncated 1184 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/onboarding.py:162
Finding

Onboarding recommends installation of unpinned third-party dependencies

Content
View full analysis
dict: try: import qrcode except ImportError: err = "缺少 qrcode 依赖,请运行: pip install qrcode pillow" print(f"{TAG} render_qr: {err}", file=sys.stderr) return {"png_path": None, "ascii_qr": None, "error": err} ``` ```python def _require_requests() -> None: if requests is None: raise RuntimeError("缺少 requests 依赖,请运行: pip install requests") ``` ### Technical Analysis The onboarding script directs users to install `qrcode`, `pillow`, and `requests` without pinned versions, hashes, a lock file, or an explicitly trusted package index. This makes the installed code dependent on the package versions and index configuration available at execution time. No evidence shows that the named packages are malicious. The security issue is the absence of reproducible dependency controls, which exposes users to compromised package releases, dependency confusion through a malicious index, or incompatible future versions. Imported Python packages execute code in the context of the user running the onboarding script. ### Attack Path 1. A required package is absent. 2. The script tells the user to run an unpinned `pip install` command. 3. The user's pip configuration references a compromised, malicious, or unintended package index, or a future package release is compromised. 4. Pip downloads and installs attacker-controlled code. 5. The package executes during installation or when imported by `onboarding.py`. 6. The malicious package obtains the permissions of the user running the script and may access environment credentials or local data. ### Impact Assessment A compromised dependency can execute arbitrary Python code with the invoking user's privileges. It may read LinkFox API keys f ...[truncated 277 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (25)

Tainted flow: 'req' from os.environ.get (line 72, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/creator_proxy.py (reported line 79)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented purpose is limited to TikTok creator data and shoppable video operations, but the detected behavior includes SMS login, API key generation, account inspection, package listing, order creation, QR-code payment generation, and payment status queries. This is a serious scope expansion into authentication and billing flows, which can expose users to credential misuse, account takeover risk, or unauthorized commercial actions.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
> 所有调用都需先经 **`linkfox-tiktok-video-auth`** 拿到达人 `accessToken` 作为 `ttsAccessToken`。

## Display Rules

1. **只呈现数据**:展示达人资料字段即可,不做主观评价。
2. **令牌安全**:不要明文输出完整 `ttsAccessToken`,仅展示掩码。

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
证码后:`python scripts/onboarding.py login <phone> <code>`(workbuddy 宿主加 `--channel workbuddy`)
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `积分/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file implements LinkFox account onboarding, SMS login, API key acquisition, plan purchase, and billing functions that are unrelated to the declared TikTok creator/profile/video capability. This mismatch materially expands the skill's privilege and data-handling scope, creating an unjustified path to collect credentials and manage account commerce under a misleading skill identity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code can create orders and generate payment QR codes, which is a billing/payment capability not justified by the skill's stated TikTok creator integration purpose. In a skill context, hidden or unnecessary commerce functions are dangerous because they enable unexpected financial actions and can be triggered under false expectations about what the skill should do.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest explicitly says the skill does not perform creator authorization, yet this file sends SMS codes, logs users in, and retrieves or generates LinkFox API tokens. That contradiction is dangerous because it creates a covert credential/token acquisition flow that users and reviewers would not expect, increasing risk of unauthorized account access and token misuse.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes capabilities that access environment variables, write files, and perform network requests, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where the runtime may permit broader actions than users or reviewers expect, increasing the chance of unintended data access or exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger rule says the skill should activate even when explicit vendor or product names are absent, based only on broad topic cues. Over-broad triggering increases the chance that user requests unrelated to this specific skill are routed into a networked workflow that handles tokens, account data, and external API calls without sufficient specificity.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation says the tool consumes credits and warns against repeated calls because of additional cost, but later states '不消耗积分'. Contradictory charging semantics can mislead users into authorizing actions they would not otherwise approve and weakens informed consent around repeated paid API usage.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill mandates saving full API responses to persistent session-scoped local files by default. Those responses can include creator profile data, product data, status information, and potentially sensitive identifiers or tokens, creating a durable local data-retention surface that raises risks of leakage, unauthorized reuse, and cross-task exposure.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill broadly instructs automatic submission of feedback for many situations, including user satisfaction signals and mismatches with intent, without clear data-minimization boundaries. This can cause unnecessary transmission of conversation-derived personal or business context to an external feedback endpoint beyond what is needed to fulfill the user request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs callers to transmit a gateway API key and a creator access token but does not include explicit guidance on secure handling, redaction, storage, or privacy implications. In an agent-skill context, this increases the risk that secrets are logged, echoed back to users, persisted in traces, or mishandled by downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents an API that publishes shoppable videos to a live external platform but does not clearly warn that this is a side-effecting action that can create publicly visible content tied to a creator account and business products. In an agent setting, missing consent and confirmation requirements can lead to unauthorized posting, reputational harm, compliance issues, and unintended commercial actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 607)May include surrounding context.


curl 示例

bash
# Get Creator Profile

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The onboarding instructions tell the operator to collect a user's phone number and handle SMS-code-based login flows, but they provide no privacy notice, consent guidance, data-minimization limits, or safe handling requirements for this sensitive personal data. In a support/onboarding context this creates a real risk of unnecessary collection, insecure transmission, retention, or misuse of phone numbers and one-time codes, especially because the skill normalizes manual handling of authentication data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script always saves the full API response locally, and those responses may contain creator profile details, shop/product associations, or video publication data tied to access tokens and sessions. Persisting full responses by default broadens the exposure window for sensitive data, especially because the code also caches responses and may place them outside the expected working directory via fallback behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module documentation promises not to write to /tmp and to fail if the current directory is not writable, but the implementation silently falls back to ~/linkfox and then the system temp directory. This can cause sensitive TikTok creator data and API responses to be written to less controlled locations than operators expect, increasing the chance of unintended disclosure on shared hosts or ephemeral environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script POSTs the provided JSON parameters to a remote API and includes SESSION_ID, MODE_ID, and APP_NAME headers. Although the module docstring describes output behavior, there is no visible confirmation prompt or explicit warning that input data and runtime metadata will be transmitted off-box.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The login flow only accepts 11-digit phone numbers and always sends the area code as +86, which enforces a specific regional/locale assumption in the user-facing behavior. There is no visible option for users to choose another country or locale, so this is a natural-language policy issue under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file presents operational instructions and examples in Chinese with embedded English terms, but it does not state that the user may choose their preferred language or locale. Under the policy, language constraints should be opt-in or clearly justified; here no such choice is documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language policy requires avoiding forced language or locale constraints unless users are given a choice or the limitation is justified. This file presents all operational instructions in Chinese and does not indicate that the skill is China-specific or otherwise intentionally restricted to Chinese-language users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.