Back to skill

Security audit

HotBee 抖音数据采集

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Douyin data-collection helper that uses HotBee APIs with expected network and API-key access, with privacy caution needed for audience analytics.

Install only if you intend to use HotBee for Douyin analytics. Use it with public or authorized links, expect live VIP calls to consume HotBee quota, and be careful with fan-profile or audience analytics because they may carry privacy obligations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This markdown file documents a skill that can retrieve and analyze '粉丝画像' (fan profiling) data and provides an example command to analyze a creator's works and fan profile. The description includes no warning about privacy implications, sensitive audience data, or the need to ensure authorized/appropriate use, which is a user-facing warning omission for a data-affecting behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.