ecommerce.tiktok-video-analytics

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes Python scripts (video_rank.py, video_detail.py) to handle communication with the Nexscope API proxy. These scripts are self-contained, use standard Python libraries (urllib, json, os), and are designed to facilitate data discovery and detailed analysis within the agent's environment.
  • [EXTERNAL_DOWNLOADS]: The skill connects to the vendor's proxy infrastructure (NEXSCOPE_PROXY_BASE) to retrieve TikTok video metrics. This external communication is the core functionality of the skill and is documented as a research tool interfacing with the Kalodata data source.
  • [DATA_EXPOSURE]: The skill implements a local storage mechanism that writes API responses to a nexscope/ directory within the current project. This allows users to access raw research data and is a documented behavior intended for offline analysis and context window optimization.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface for external data via API responses.
  • Ingestion points: Data enters the context through API responses processed by video_rank.py and video_detail.py.
  • Boundary markers: Results are presented in structured tables or profiles, separating external data from agent instructions.
  • Capability inventory: The skill's scripts are restricted to HTTP communication, local file writing, and JSON processing; no dangerous execution capabilities (like eval or generic subprocess calls) are exposed.
  • Sanitization: Structural validation is provided through standard JSON parsing.
  • [SAFE]: The skill follows security best practices by recommending the use of environment variables for API key management and provides clear user guidance on credit usage and data provenance.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 12:45 AM
Security Audit — agent-trust-hub — ecommerce.tiktok-video-analytics