Back to skill

Security audit

抖音每日点赞飙升榜

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Douyin ranking lookup tool that uses a RedFox API key to fetch trend data, with no evidence of hidden persistence, destructive behavior, or credential misuse.

Before installing, verify that you trust RedFoxHub as the API provider and understand that your configured API key will be sent to redfox.hk when queries run. Be aware that broad surge-ranking phrasing may activate the skill unexpectedly; use explicit Douyin wording for best control.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger phrases are broad and overlapping, such as generic terms for rankings, growth, or 'surge', which can cause the skill to activate on unrelated user requests. Mis-triggering can silently route conversations to this skill, causing unintended external API calls and disclosure of user query content to a third-party service.

Static analysis

No suspicious patterns detected.