tiktok-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses scripts/crawlora.sh to execute curl commands. The script includes robust validation for HTTP methods (GET/POST) and uses regex-based whitelisting for TikTok API paths to prevent command injection.
  • [EXTERNAL_DOWNLOADS]: The skill connects to https://api.crawlora.net to retrieve TikTok data. This domain belongs to the skill's vendor and is used appropriately for the skill's research function.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves untrusted data from TikTok (comments, captions). Evidence Chain: 1. Ingestion points: Profile and video endpoints in scripts/crawlora.sh. 2. Boundary markers: Not explicitly enforced in data output. 3. Capability inventory: curl network calls restricted by a whitelist. 4. Sanitization: Path and parameter validation in the helper script.
  • [DATA_EXFILTRATION]: The skill safely handles the CRAWLORA_API_KEY by writing it to a temporary curl configuration file with restricted permissions, preventing it from leaking via process lists or shell history. The script also explicitly rejects the use of the @ character in query parameters to prevent the accidental disclosure of local files via curl's file-reading shorthand.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:44 AM
Security Audit — agent-trust-hub — tiktok-research