抖音每日点赞飙升榜

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Douyin ranking lookup tool that uses a disclosed RedFox API key and does not show hidden or destructive behavior.

Install only if you are comfortable giving a RedFox API key to this skill's documented redfox.hk endpoint. Treat the subscription feature as opt-in: confirm the category and delivery time, and check how to cancel or change recurring notifications before relying on it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
88% confidence
Finding
The guide explicitly instructs the agent to offer subscription and scheduled push behavior, but it does not require clear user consent language, notice of ongoing notifications, or any explanation of what data will be retained to support the subscription. This can lead to users being enrolled in recurring notifications without fully understanding the persistence and handling implications, which is a privacy and trust risk even if no sensitive data is directly exposed in this file.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal