ecommerce.tiktok-creator-analytics
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes external content (such as creator bios, handles, and nicknames) from TikTok via the Kalodata data source, which introduces a surface for indirect prompt injection.
- Ingestion points: Data enters the agent's context through the JSON responses returned by
scripts/creator_detail.pyandscripts/creator_rank.py. - Boundary markers: The instructions in
SKILL.mddo not specify delimiters or provide guidance to the agent to treat the retrieved data as potentially untrusted. - Capability inventory: The skill possesses network read capabilities (via
urllib) and local file-write capabilities for caching and data storage in thenexscope/directory. - Sanitization: The Python scripts do not perform explicit sanitization or filtering of the external strings (e.g.,
creator_bio) before they are displayed or saved to the local filesystem.
Audit Metadata