Skills maxhub-tiktok
๐Ÿ“ฆ

maxhub-tiktok

v3.2.0 Content revision r1 High Risk ๐ŸŒ Network access๐Ÿ”‘ Env variablesโš™๏ธ External commands

Analyze TikTok Data With MaxHub

TikTok research often needs many video, user, search, and ad endpoints. This skill routes requests through MaxHub references and returns structured summaries.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "maxhub-tiktok" from https://skillstore.io/skills/xiewxx-maxhub-tiktok.md and its manifest at https://skillstore.io/api/skills/xiewxx-maxhub-tiktok/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "maxhub-tiktok". Analyze creator @example for recent performance.

Expected outcome:

The report lists profile metrics, recent video themes, engagement changes, and endpoints that returned no data.

Using "maxhub-tiktok". Find TikTok ads for a skincare product in the United States.

Expected outcome:

The response groups matching ads by creative angle, visible engagement, product references, and missing regional coverage.

Using "maxhub-tiktok". Compare video search results for two keywords.

Expected outcome:

The comparison highlights result volume, common creators, engagement ranges, and which keyword has stronger current signals.

Security Audit

High Risk
v4 โ€ข 7/8/2026 Open versioned report

Most static hits are Markdown documentation false positives, including backticks, endpoint IDs, sample URLs, and bilingual text. Confirmed risk remains because the skill handles a MaxHub API key, may transmit TikTok cookies, and documents anti-abuse and interaction capabilities.

9
Files scanned
9,970
Lines analyzed
9
Review items
0
False positives ignored

Confirmed security concerns (3)

High
Credential and Session Cookie Transmission to Third Party
The skill sends MAXHUB_API_KEY as a Bearer token to MaxHub and warns that some endpoints may require platform session cookies.
The credential header and cookie requirements are explicit in the skill and reference files. This is intentional third-party credential handling, not scanner noise.
High
Anti-Abuse Token and Guest Cookie Generation
The references include endpoints for TikTok encryption headers, guest cookies, real msToken generation, and randomized browser fingerprint data.
The documentation directly describes generating TikTok request headers, guest cookies, and randomized browser fingerprint data for crawler resistance.
High
Read-Only Claim Conflicts With Interaction Actions
The skill claims read-only operation, but README content lists like, follow, comment, collect, and forward actions, and references include private-message deep links.
The read-only statement is explicit, while separate files advertise interaction actions and a private-message deep link. Some actions may only generate links, but the scope mismatch is real.
Capability review items (9)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
Generic API/secret keys
Auth: `Authorization: Bearer $MAXHUB_API_KEY`
This instructs use of MAXHUB_API_KEY as a Bearer token for MaxHub API calls. The token is intentionally sent to a third-party service.
High
Generic API/secret keys
Auth: `Authorization: Bearer $MAXHUB_API_KEY`
This instructs use of MAXHUB_API_KEY as a Bearer token for MaxHub API calls. The token is intentionally sent to a third-party service.
High
Generic API/secret keys
Auth: `Authorization: Bearer $MAXHUB_API_KEY`
This instructs use of MAXHUB_API_KEY as a Bearer token for MaxHub API calls. The token is intentionally sent to a third-party service.
High
Generic API/secret keys
Auth: `Authorization: Bearer $MAXHUB_API_KEY`
This instructs use of MAXHUB_API_KEY as a Bearer token for MaxHub API calls. The token is intentionally sent to a third-party service.
High
Generic API/secret keys
primaryEnv: MAXHUB_API_KEY
The skill declares MAXHUB_API_KEY as a required sensitive environment value. This is expected for the API integration but grants the skill access to a secret.
High
Generic API/secret keys
- MAXHUB_API_KEY
The skill declares MAXHUB_API_KEY as a required sensitive environment value. This is expected for the API integration but grants the skill access to a secret.
High
Generic API/secret keys
- name: MAXHUB_API_KEY
The skill declares MAXHUB_API_KEY as a required sensitive environment value. This is expected for the API integration but grants the skill access to a secret.
High
Generic API/secret keys
Use the configured `MAXHUB_API_KEY` value as the `Authorization: Bearer` request header.
This instructs use of MAXHUB_API_KEY as a Bearer token for MaxHub API calls. The token is intentionally sent to a third-party service.
High
Generic API/secret keys
maxhub_auth_header="Authorization: Bearer ${MAXHUB_API_KEY}"
This instructs use of MAXHUB_API_KEY as a Bearer token for MaxHub API calls. The token is intentionally sent to a third-party service.

Risk Factors

๐ŸŒ Network access (64)
_meta.json:6 _meta.json:7 references/api-ads-analytics.md:660 references/api-ads-analytics.md:662 references/api-ads-analytics.md:663 references/api-ads-analytics.md:664 references/api-ads-analytics.md:665 references/api-search.md:564 references/api-search.md:574 references/api-search.md:666 references/api-search.md:670 references/api-search.md:671 references/api-search.md:675 references/api-search.md:676 references/api-user.md:57 references/api-user.md:479 references/api-user.md:482 references/api-user.md:483 references/api-user.md:487 references/api-user.md:488 references/api-user.md:495 references/api-user.md:496 references/api-video.md:4305 references/api-video.md:4326 references/api-video.md:4328 references/api-video.md:4517 references/api-video.md:4521 references/api-video.md:4522 references/api-video.md:4526 references/api-video.md:4527 references/api-video.md:4665 references/api-video.md:4669 references/api-video.md:4970 references/api-video.md:4974 references/api-video.md:4980 references/api-video.md:4984 references/api-video.md:5319 references/api-video.md:5321 references/api-video.md:5322 references/api-video.md:5323 references/api-video.md:5324 references/api-video.md:5431 references/api-video.md:5437 references/api-video.md:5541 references/api-video.md:5542 references/api-video.md:5658 references/api-video.md:5662 references/api-video.md:5663 references/api-video.md:5672 references/api-video.md:5740 references/api-video.md:5742 references/api-video.md:5747 references/api-video.md:5749 SKILL.md:18 SKILL.md:22 SKILL.md:30 SKILL.md:32 SKILL.md:45 SKILL.md:53 SKILL.md:57 SKILL.md:75 SKILL.md:77 SKILL.md:98 SKILL.md:109
๐Ÿ”‘ Env variables (16)
โš™๏ธ External commands (19)
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/xiewxx-maxhub-tiktok/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/xiewxx-maxhub-tiktok/security.svg)](https://skillstore.io/skills/xiewxx-maxhub-tiktok?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/xiewxx-maxhub-tiktok?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/xiewxx-maxhub-tiktok/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/xiewxx-maxhub-tiktok.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

XieWxx. (2026). maxhub-tiktok security audit report (audit version 4) [Author version 3.2.0]. Skillstore. https://skillstore.io/skills/xiewxx-maxhub-tiktok/audits/4

BibTeX citation

@techreport{xiewxx-xiewxx-maxhub-tiktok-2026, author = {XieWxx}, title = {maxhub-tiktok security audit report (audit version 4)}, institution = {Skillstore}, year = {2026}, number = {4}, url = {https://skillstore.io/skills/xiewxx-maxhub-tiktok/audits/4}, note = {Author version 3.2.0} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "maxhub-tiktok security audit report (audit version 4)" version: "3.2.0" type: report authors: - name: "XieWxx" date-released: "2026-07-08" url: "https://skillstore.io/skills/xiewxx-maxhub-tiktok/audits/4" identifiers: - type: other value: "skillstore:xiewxx-maxhub-tiktok:audit:4" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
59
Architecture
100
Maintainability
87
Content
68
Community
100
Spec Compliance

What You Can Build

Profile Creator Performance

Compare creator profile data, recent posts, engagement signals, and audience metrics from MaxHub endpoints.

Research Ads and Keywords

Find TikTok ads, keyword insights, product signals, and creative patterns for campaign planning.

Map API Workflows

Translate a TikTok data question into likely MaxHub endpoints, parameters, and response expectations.

Try These Prompts

Fetch Video Details
Use maxhub-tiktok to retrieve details for this TikTok video URL: [url]. Summarize views, engagement, author, and data limits.
Analyze a Creator
Analyze TikTok creator [handle]. Find profile data, recent posts, engagement patterns, and any missing fields.
Compare Ad Examples
Compare TikTok ads for [brand or product] in [regions]. Include creative themes, engagement signals, and source limitations.
Build Market Report
Create a TikTok market report for [category] in [country]. Use search, creator, ad, and product analytics endpoints. State credential limits.

Best Practices

  • Use scoped or test credentials when possible.
  • Avoid sending full browser cookies unless the endpoint requires them.
  • Disclose third-party data use and verify TikTok platform compliance before automation.

Avoid

  • Do not provide personal session cookies for casual analysis.
  • Do not automate likes, follows, comments, or messages without explicit authorization.
  • Do not treat third-party API results as official TikTok records.

Frequently Asked Questions

Does this skill require an API key?
Yes. It requires MAXHUB_API_KEY for MaxHub API requests.
Can it work without network access?
No. The skill is designed around calls to the MaxHub API service.
Does it support English and Chinese?
Yes. The skill instructions and references support both languages.
Will it store my TikTok cookie?
The skill text says cookies are sent to MaxHub for requests. Storage behavior depends on the provider.
Is every endpoint read-only?
No evidence found that every referenced capability is read-only. Review interaction and deep-link endpoints before use.
Can Claude, Codex, or Claude Code use it?
Yes. The report declares support for Claude, Codex, and Claude Code.

Developer Details

Author

XieWxx

License

MIT-0

Author version

v3.2.0

Skillstore revision

r1

Ref

64ca8af0f54a325752f08bd54e52151061ea659a

Maintenance freshness

7/20/2026

Usage

7 downloads ยท 82 views

File structure

๐Ÿ“ references/

๐Ÿ“„ api-ads-analytics.md

๐Ÿ“„ api-search.md

๐Ÿ“„ api-user.md

๐Ÿ“„ api-video.md

๐Ÿ“„ param-mappings.md

๐Ÿ“„ _meta.json

๐Ÿ“„ README_CN.md

๐Ÿ“„ README.md

๐Ÿ“„ SKILL.md