AGENT LAB: SKILLS

tiktok-automation

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill describes tools that fetch content from TikTok (e.g., video lists, profiles) which could contain malicious prompts. 1. Ingestion points: TIKTOK_LIST_VIDEOS and TIKTOK_GET_USER_PROFILE in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Content publishing tools like TIKTOK_PUBLISH_VIDEO and TIKTOK_POST_PHOTO. 4. Sanitization: Not specified in documentation.
  • [No Code] (SAFE): The skill consists entirely of markdown documentation and tool definitions without executable logic, scripts, or binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 04:58 PM