discovering-tiktok-shop-sellers-by-niche

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides examples for running a local script (scripts/run_actor.js) and using curl to interact with the Apify REST API. These are standard methods for interacting with the described service and do not execute arbitrary or dangerous commands.- [DATA_EXPOSURE_&_EXFILTRATION]: The skill requires an APIFY_TOKEN environment variable. It correctly recommends storing this in an environment variable or a .env file, which is a standard security best practice for managing secrets.- [EXTERNAL_DOWNLOADS]: The skill references the apidojo/tiktok-scraper actor on Apify. This is a functional dependency related to the skill's primary purpose of niche research and scraping.- [INDIRECT_PROMPT_INJECTION]: The skill processes data from TikTok (hashtags, posts, descriptions). While this is an ingestion surface for untrusted data, the skill's purpose is data extraction and mapping, not executive action based on the content, which poses minimal risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 06:42 PM
Security Audit — agent-trust-hub — discovering-tiktok-shop-sellers-by-niche