Tiktok Influencer Tracker
Analysis
The skill is a coherent TikTok creator-management guide, but users should notice that it allows Bash and may store business, shipment, and commission data.
Findings (2)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
Checks for instructions or behavior that redirect the agent, misuse tools, execute unexpected code, cascade across systems, exploit user trust, or continue outside the intended task.
allowed-tools: Bash
The skill permits shell access even though the provided artifacts are instruction-only and do not include an implementation or required binary.
Checks for exposed credentials, poisoned memory or context, unclear communication boundaries, or sensitive data that could leave the user's control.
creator add <username> # add creator to management database - **Sample shipment info** — product sent, date shipped, tracking number - **Commission data** — sales attributed to each creator
The skill is designed to maintain creator records and handle shipment, sales, and commission data, which may be sensitive business information if stored or reused.
