tikhub-api-helper

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The api_client.py script is designed to include the user's secret API token in the Authorization header of every request it makes. However, the script lacks validation to ensure these tokens are only sent to trusted TikHub domains.
  • Evidence: In the _build_url method of api_client.py, the script returns the path argument verbatim if it starts with http. The request method then uses this URL with urllib.request.urlopen while attaching the Authorization header. This allows a potentially malicious actor to provide a full URL to an attacker-controlled server, causing the agent to exfiltrate the secret token.
  • [COMMAND_EXECUTION]: The skill relies on the agent executing local Python scripts to perform its tasks.
  • Evidence: The instructions in SKILL.md guide the agent to run python api_searcher.py and python api_client.py with various arguments to search for and call API endpoints.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data fetched from various social media platforms (TikTok, Douyin, etc.), creating an attack surface for indirect prompt injection.
  • Ingestion points: Social media data returned by the TikHub API endpoints, such as comments and profile metadata.
  • Boundary markers: No explicit instructions or delimiters are provided to help the agent distinguish between data content and instructions.
  • Capability inventory: The agent has the ability to make network requests (via api_client.py) and read local files (via api_searcher.py).
  • Sanitization: No sanitization or filtering of the API responses is performed before the data is presented to the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 02:56 AM