Back to skill

Security audit

TikTok App Marketing is an AI-agent skill that automates TikTok slideshow marketing for any app or product — researching competitors, generating AI images, adding hook and CTA text overlays, creating TikTok drafts and cross-posting to Instagram, YouTube and Threads via PosteAhora, tracking per-post analytics, and iterating on the hooks and CTAs that drive views and paying users (with optional RevenueCat conversion tracking).

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a disclosed TikTok marketing workflow, but it includes anti-detection account warmup coaching and broad analytics, credential, and scheduled-job behavior that users should review carefully.

Install only if you are comfortable granting an agent access to social posting, analytics, and possibly RevenueCat revenue data. Keep API keys in environment variables or a private secrets store, disable or review any daily cron job, approve each public post or cross-post, and avoid using the TikTok warmup guidance to bypass platform enforcement or automation rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill directs the agent to install host-level dependencies, build tools, and global CLI software, which expands its authority beyond normal content-marketing tasks and increases the risk of unnecessary system modification. In an agent setting, this can lead to privilege misuse, supply-chain exposure from unvetted packages, and changes on the user's machine that are not strictly required for safe skill execution.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
The account warm-up guidance is an evasion tactic designed to make a fresh TikTok account appear human before automation begins, specifically to avoid bot detection and throttling. This crosses from normal marketing automation into deliberate platform-manipulation behavior and could cause the agent to coach users through deceptive actions that violate platform rules.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The file instructs the agent to pull analytics and RevenueCat conversion events, correlate them to post publish times, and message the user with performance summaries, but it does not include any user-facing notice, consent check, or data-minimization guidance. This creates a real privacy/compliance risk because engagement data, attribution data, and purchase/trial events may be processed and combined without the user being clearly warned about collection, linkage, retention, or third-party data handling.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The template hard-codes generation of a 'young woman' for beauty/cosmetics content, which bakes in demographic bias and removes user choice over age and gender representation. In a marketing automation skill that can mass-produce content, this can systematically produce exclusionary or stereotype-reinforcing outputs and create brand, compliance, and discrimination risks at scale.

Ssd 4

Medium
Confidence
99% confidence
Finding
The staged warm-up instructions explicitly coach the user to perform selective scrolling, sparse liking, niche-following, and casual posting so the account is classified as a real person before automated marketing starts. This is a textbook attempt to evade anti-abuse systems and normalize deceptive platform behavior, making the skill materially riskier in context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:278