tiktok-marketing

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill bundle follows best practices for security and transparency. It avoids hardcoded credentials by using environment variables and provides a utility script (check_no_secrets.py) to prevent accidental exposure of secrets.
  • [COMMAND_EXECUTION]: The skill includes a 'Tier 2' advanced feature in lib/backend_selector.py that allows users to define a custom posting command via the TIKTOK_SKILLS_CUSTOM_POSTER environment variable. This feature is intended for advanced users building their own posters on the official TikTok API and requires manual configuration by the user.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it fetches external content such as TikTok comments and video descriptions via the Apify API. While this untrusted data enters the agent's context for analysis, the risk is low as the skill's primary purpose is content planning and drafting, and it does not have high-privilege capabilities that could be easily abused.
  • [EXTERNAL_DOWNLOADS]: The skill makes authenticated network requests to established services including api.publora.com, api.apify.com, and api.pixfaro.com. These integrations are central to the skill's functionality and are clearly documented for the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:04 AM
Security Audit — agent-trust-hub — tiktok-marketing