This skill clearly aims to auto-publish Douyin articles, but it can post to a live account by default and uses an unsafe shell command path with user-influenced filenames.
Install only if you intentionally want an agent to generate content and publish to a linked Douyin account. Use --skip-publish or a manual review workflow first, inspect the generated article and image, avoid sensitive prompts, and treat logs as potentially sensitive. The publisher should replace shell=True with argument-list execution, narrow triggers to explicit Douyin publishing requests, and add a required publish confirmation or dry-run default.