playlet-douyin-feed
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill retrieves data from
redfox.hk. This is the official API for the vendor 'redfox-data' and is required for the skill's functionality. - [COMMAND_EXECUTION]: The script
playlet_douyin_daily.pyis executed to process content and generate reports locally; this behavior is legitimate and transparent. - [CREDENTIALS_UNSAFE]: The skill uses the
REDFOX_API_KEYenvironment variable for authentication, following security best practices for credential management. - [DATA_EXFILTRATION]: No unauthorized data transfer was detected. The script only sends necessary query parameters to the vendor's API.
- [PROMPT_INJECTION]: The skill processes external content from the vendor API. It provides the agent with a rigid markdown template for output, which serves as a boundary to prevent the agent from being influenced by any potential instructions embedded in the data titles.
Audit Metadata