Back to skill

Security audit

抖音七日点赞飙升榜

Security checks across malware telemetry and agentic risk

Overview

This skill is a Douyin ranking query tool that uses a RedFox API key and has some subscription language users should treat as opt-in only.

Install only if you are comfortable creating and storing a RedFox API key for this skill. Treat any daily subscription or push-delivery feature as requiring explicit opt-in, and confirm where it is stored and how to cancel it before enabling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The guide instructs the agent to offer a subscription and scheduled push service even though the skill is described as a query tool. This expands behavior beyond the declared scope, which can mislead the orchestrator or user into collecting preferences or initiating persistent actions not covered by the manifest or expected permissions.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
This section explicitly claims support for user subscriptions with scheduled delivery, which is a materially different capability from one-time ranking queries. In a skill environment, undocumented persistence or push behavior can cause unauthorized data retention, unsolicited notifications, or capability confusion if the agent attempts to perform actions the platform has not approved.

Missing User Warnings

Low
Confidence
81% confidence
Finding
The skill instructs users to configure a long-lived API key in a config file or shell environment without any guidance on secret handling, storage risks, rotation, or scope minimization. While not overtly malicious, this can lead to accidental credential exposure through committed dotfiles, shared shell history, screenshots, logs, or overly broad reuse of the same key.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.