TikTok Business

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed TikTok Business connector wrapper focused on reading GMV Max and campaign data, with no artifact-backed malicious behavior found.

Install this only if you use OOMOL and want an agent to read TikTok Business and GMV Max data from your connected account. Review the oo CLI install step and connected-account scopes, and treat any future added create, update, post, or delete action as requiring explicit user confirmation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The manifest and metadata frame the skill as suitable for 'searching and reading data,' but the body explicitly discusses create, update, send, post, delete, and remove actions that can change TikTok Business state. This mismatch can mislead orchestrators or users into invoking the skill under a read-only assumption, increasing the risk of unintended state-changing operations.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger text says to use this skill for 'ANY TikTok Business request,' which is overly broad and can cause the agent to invoke it for incidental mentions or tasks better handled by safer, narrower tooling. Over-broad routing increases attack surface and raises the chance of unnecessary connector access or accidental execution in the wrong context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal