tikhub-api-helper
Warn
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The
api_client.pyscript is designed to include the user's secret API token in theAuthorizationheader of every request it makes. However, the script lacks validation to ensure these tokens are only sent to trusted TikHub domains. - Evidence: In the
_build_urlmethod ofapi_client.py, the script returns thepathargument verbatim if it starts withhttp. Therequestmethod then uses this URL withurllib.request.urlopenwhile attaching theAuthorizationheader. This allows a potentially malicious actor to provide a full URL to an attacker-controlled server, causing the agent to exfiltrate the secret token. - [COMMAND_EXECUTION]: The skill relies on the agent executing local Python scripts to perform its tasks.
- Evidence: The instructions in
SKILL.mdguide the agent to runpython api_searcher.pyandpython api_client.pywith various arguments to search for and call API endpoints. - [INDIRECT_PROMPT_INJECTION]: The skill processes data fetched from various social media platforms (TikTok, Douyin, etc.), creating an attack surface for indirect prompt injection.
- Ingestion points: Social media data returned by the TikHub API endpoints, such as comments and profile metadata.
- Boundary markers: No explicit instructions or delimiters are provided to help the agent distinguish between data content and instructions.
- Capability inventory: The agent has the ability to make network requests (via
api_client.py) and read local files (viaapi_searcher.py). - Sanitization: No sanitization or filtering of the API responses is performed before the data is presented to the agent.
Audit Metadata