The skill mostly does what it advertises, but it builds shell commands from user-supplied links and paths, which creates a real local command-execution risk.
Review before installing. Use only with trusted Douyin links and safe output paths, because a crafted link or path could be interpreted by the local shell. Treat the workflow as networked: the Douyin URL is submitted to hellotik.app, media is downloaded from resolved CDN URLs, and generated files remain on disk unless cleanup is requested. Do not enable or extend Feishu upload unless you understand exactly which tenant and destination IDs will receive the content.