extracting-tiktok-comments-for-research

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The purpose is coherent, credentials are mostly proportionate, and network endpoints are official Apify services, but the skill forwards the user's APIFY_TOKEN into a third-party community actor execution path. This is not confirmed malware, yet it creates meaningful trust and credential-forwarding risk beyond a simple documentation or direct-API integration.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Sep 2, 2026, 07:25 PM
Package URL
pkg:socket/skills-sh/apidojo-io%2Fapidojo-skills%2Fextracting-tiktok-comments-for-research%2F@230b9b598df5afe2b1a335648aaffaa9715326b25f484b275ccb94fcaa5a9bf5
Security Audit — socket — extracting-tiktok-comments-for-research