tiktok-research

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from an external platform (TikTok) which creates a risk for indirect prompt injection attacks where malicious instructions embedded in video descriptions, comments, or creator profiles could attempt to influence the agent's behavior.
  • Ingestion points: The skill ingests data through various tools including tiktok_app_v3_general_search_result, tiktok_app_v3_creator_info, tiktok_app_v3_one_video, and tiktok_app_v3_live_room_info (identified in SKILL.md and references/sandbase-api-map.md).
  • Boundary markers: There are no explicit instructions or delimiters defined to separate untrusted tool outputs from the agent's system instructions.
  • Capability inventory: The skill utilizes sandbase_call_tool to interact with the SandBase API for data retrieval and research.
  • Sanitization: The skill does not specify any sanitization, filtering, or validation steps for the content retrieved from TikTok before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — tiktok-research