tiktok
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references various official UnifAPI documentation and platform resources (unifapi.com, docs.unifapi.com, github.com/unifapi-agent). These are consistent with the vendor's own infrastructure and present no security risk.
- [COMMAND_EXECUTION]: There are no shell commands, scripts, or automated tools executed by this skill. It functions purely as a documentation layer for an AI agent to interface with a separate MCP (Model Context Protocol) server.
- [DATA_EXFILTRATION]: The skill is explicitly described as 'read-only' and 'eyes, not hands.' It maps endpoints for reading public data (followers, video counts, hashtag trends) and contains no mechanisms to exfiltrate private user data or credentials.
- [CREDENTIALS_UNSAFE]: No hardcoded API keys or secrets are present. The skill relies on external OAuth connection via the standard
unifapiskill, following best practices for secret management. - [PROMPT_INJECTION]: The skill uses clear instructions to define agent behavior for data research without attempting to bypass safety filters or override system prompts.
Audit Metadata