other
- Location
SKILL.md:19- Finding
Overbroad Collection and External Processing of Private Communications
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 19-26 and 121-140
Vulnerability Type: Sensitive data overcollection and third-party disclosure
Risk Level: MediumEvidence
markdown The skill automatically ingests comments, DMs, and replies from YouTube, TikTok, Instagram, and email—then applies advanced NLP analysis to extract: - **Intent signals**: Buying intent, pain points, feature requests, unmet needs - **Sentiment velocity trends**: Identify whether audience sentiment is accelerating positive or negative over time - **Emerging topics**: Flag discussion patterns before they trend publicly - **Churn indicators**: Early warning signs of audience dissatisfaction or drift - **Audience persona shifts**: Detect changes in who's engaging and whyRelevant configuration includes:
bash # TikTok Business API (for comment/DM data) export TIKTOK_ACCESS_TOKEN="your-tiktok-access-token" export TIKTOK_BUSINESS_ACCOUNT_ID="your-account-id" # Instagram Graph API (for comments and DMs) export INSTAGRAM_BUSINESS_ACCOUNT_ID="your-instagram-business-id" export INSTAGRAM_ACCESS_TOKEN="your-instagram-access-token" # Anthropic Claude for NLP analysis export ANTHROPIC_API_KEY="your-claude-api-key" # Optional: Gmail for email feedback analysis export GOOGLE_SERVICE_ACCOUNT_JSON="/path/to/service-account.json" # Optional: Slack notifications for alerts export SLACK_WEBHOOK_URL="https://hooks.slack.com/services/YOUR/WEBHOOK"Technical Analysis
The declared sentiment-analysis functionality can legitimately require access to user-selected messages. However, the Skill encourages broad ingestion of comments, private direct messages, and email threads, as well as connecting all available platforms and analyzing substantial historical windows.
Private messages and email threads may contain names, contact details, account information, confidential business material, authent ...[truncated 2555 chars]
- Remediation
View remediation
Remediation Suggestions
- Default to public comments from only the platform and time range explicitly requested by the user.
- Require separate, explicit approval before accessing DMs, email, or other non-public communications.
- Request read-only, source-specific OAuth scopes instead of broad account permissions.
- Present the intended data categories, recipients, time range, and estimated record count before collection.
- Redact names, email addresses, phone numbers, access tokens, authentication links, payment data, and unrelated message content before external processing.
- Prefer local aggregation or classification where possible; otherwise disclose the external model provider and obtain user approval before transmission.
- Set
include_samplestofalseby default. If samples are necessary, use pseudonymized excerpts and require explicit opt-in. - Define retention and deletion periods for source data, model requests, intermediate files, reports, and notification payloads.
- Prevent raw DMs or emails from being sent through Slack alerts; alerts should contain aggregate findings and links to access-controlled reports.
- Document recipient access controls, audit logging, encryption requirements, and applicable data-processing agreements.
