Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The documentation and agent rules claim that all outbound calls go only to open.tiktokapis.com, but the file-upload flow performs a PUT to a server-provided upload_url that may point to a different host. This mismatch can weaken trust boundaries and host allowlisting assumptions, causing the agent to send local file contents to an unvalidated destination if the URL is malicious, misissued, or unexpectedly broad.
