expert-douyin
Warn
Audited by Socket on Sep 16, 2026
2 alerts found:
Securityx2SecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the business purpose is coherent for Douyin operations, but the skill’s effective footprint depends on multiple opaque internal tools and cross-skill delegation that are not independently verifiable. No direct malicious behavior is shown, yet unverifiable helper CLIs, delegated session handling, and autonomous publishing make the trust and execution chain too broad to treat as benign.
Confidence: 82%Severity: 76%
Securitytools/douyin-comments/SKILL.md
MEDIUMSecurityMEDIUM
tools/douyin-comments/SKILL.md
SUSPICIOUS:用途与“抓取抖音评论”基本一致,但认证与数据流不走官方 open API,而是依赖共享网页会话 cookie/UA/签名;再加上两个 CLI 来源不可验证,整体风险高于普通文档型技能。未见明确恶意外传或载荷执行,因此更像高风险/边界模糊的抓取工具,而非确认恶意。
Confidence: 88%Severity: 72%
Audit Metadata