ecommerce.tiktok-video-download-url

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external TikTok URLs and displays metadata returned from an API, creating a surface where malicious instructions could be embedded in video data. Ingestion points include the url parameter and the script input. No boundary markers are present to isolate the external content. The skill has capabilities for network requests and file system writes, and it performs no specific sanitization of the resulting metadata strings.
  • [DATA_EXFILTRATION]: The execution script scripts/echotik_get_video_download_url.py attempts to access the user's home directory path (~) to create a storage directory (~/nexscope) when the local directory is unwritable, exposing file system paths.
  • [COMMAND_EXECUTION]: The skill relies on the execution of a Python script to perform network operations and local file management.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 12:46 AM
Security Audit — agent-trust-hub — ecommerce.tiktok-video-download-url