tiktok-api

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from TikTok APIs (including video titles and captions) and appends it to a local wiki log without sanitization. This presents a surface for indirect prompt injection if an attacker-controlled video title contains instructions that could influence an agent reading the wiki log later.\n
  • Ingestion points: API responses from TikTok Display and Business Account APIs (e.g., video titles and captions).\n
  • Boundary markers: The skill uses Markdown headers and YAML frontmatter in 02-DOCS/wiki/shortform/ files, but provides no instructions for escaping these fields.\n
  • Capability inventory: Writing to local Markdown files using both Python and Node.js implementations.\n
  • Sanitization: No explicit sanitization or validation of the external strings is prescribed before they are logged to the wiki.\n- [COMMAND_EXECUTION]: The skill includes scripts/verify.sh, a bash script for static analysis. It scans local directories for hardcoded TikTok client secrets and access tokens. It is a utility for improving security, not a malicious payload.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:57 AM
Security Audit — agent-trust-hub — tiktok-api