Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add binggandata/bggg-skills --skill bggg-tiktok-downloadergit clone --depth 1 https://github.com/binggandata/bggg-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/binggandata/bggg-skills/bggg-tiktok-downloader)<a href="https://agentmods.dev/skills/binggandata/bggg-skills/bggg-tiktok-downloader"><img src="https://agentmods.dev/badge/skills/binggandata/bggg-skills/bggg-tiktok-downloader/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/binggandata/bggg-skills/bggg-tiktok-downloader"><img src="https://agentmods.dev/badge/skills/binggandata/bggg-skills/bggg-tiktok-downloader.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high YARA Match · line 56 YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).Fix: Remove the malware payload or compromised file entirely. Investigate how it entered the skill and audit all other artifacts for additional indicators of compromise.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00109 | $0.00815 |
| Opus 5 | $0.00055 | $0.00407 |
| Sonnet 5 | $0.00022 | $0.00163 |
| Haiku 4.5 | $0.00011 | $0.00081 |
Grade A, and why
bggg-tiktok-downloader scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
BGGG TikTok Downloader
目标
把 TikTok 视频下载到本地项目目录。优先使用随 skill 捆绑的确定性脚本:
python3 bggg-tiktok-downloader/scripts/download_tiktok.py "<TikTok URL>"
脚本优先使用 yt-dlp 负责单视频和博主列表下载;单视频在 yt-dlp 不可用或失败时使用 tikwm 兜底。若设置 TIKTOKDOWNLOADER_ROOT 或传 --tiktokdownloader-root,脚本会尝试引用本地 TikTokDownloader 的链接识别规则;没有该目录也可以运行。
工作流
- 识别输入类型:
- 包含
/video/或/photo/的 TikTok 链接按单个作品处理。 https://www.tiktok.com/@username这类主页链接按博主处理。- 用户指定“下载 N 条/前 N 个/最新 N 个”时传
--limit N。 - 用户说“全部”或只给博主链接且无数量时传
--limit 0,表示不限制数量。
- 包含
- 选择输出目录。默认是本 skill 下的
projects/downloads/tiktok;用户指定目录时传--output-dir。 - 运行脚本并查看 JSON 输出里的
manifestPath、itemCount和items[].filePath。 - 如果后续要转写音轨,把输出的视频目录交给
bggg-tiktok-readvideo。
常用命令
下载单个视频:
python3 bggg-tiktok-downloader/scripts/download_tiktok.py "https://www.tiktok.com/@user/video/1234567890123456789" --thumbnail
下载某博主前 30 个视频:
python3 bggg-tiktok-downloader/scripts/download_tiktok.py "https://www.tiktok.com/@user" --mode author --limit 30 --thumbnail
下载某博主全部可见视频:
python3 bggg-tiktok-downloader/scripts/download_tiktok.py "https://www.tiktok.com/@user" --mode author --limit 0 --thumbnail
需要登录态时,可以显式使用浏览器 Cookie:
python3 bggg-tiktok-downloader/scripts/download_tiktok.py "https://www.tiktok.com/@user" --mode author --limit 20 --cookies-browser chrome
注意事项
- 只下载用户有权保存和处理的内容。遇到私密账号、地区限制或风控时,需要用户提供可用 Cookie。
- 不要提交 Cookie 文件、浏览器 profile、下载结果、
.info.json或采集 manifest 到公开仓库。 - 作者批量下载依赖
yt-dlp;单视频可走 tikwm 兜底。 - 输出目录内会生成
.bggg-tiktok-download-archive.txt跳过重复视频,以及download_manifest.json记录结果。
更多实现细节按需读取 references/implementation-notes.md。
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 67 lines · 109 tokens per session scan A 099567fda7c3
bggg-tiktok-downloader is a skill published in the GitHub repository binggandata/bggg-skills (594 stars, last pushed 1mo ago), licensed MIT. It adds 109 tokens to every session and 815 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
debug-optimize-lcp
Guides debugging and optimizing Largest Contentful Paint (LCP) using Chrome DevTools MCP tools. Use this skill whenever the user asks about LCP performance, slow page loads, Core Web Vitals optimization, or wants to understand why their page's main content takes too long to appear. Also use when the user mentions…
opencli-sitemap-author
Use when creating or maintaining OpenCLI site sitemaps: agent-facing navigation, page-state, action, workflow, API-reference, pitfall, and fallback knowledge for a website. Use after browser exploration discovers durable site context, when a sitemap is stale, or when promoting local site knowledge into the repo.
interactive-login
How to complete browser/interactive logins (aws / gh / glab / gcloud). The platform backgrounds the login poller so it survives the human's browser round-trip — and when that does NOT work.
pinchtab-mcp
Use this skill when a task requires browser automation through PinchTab's MCP server connected to a remote browser instance. Covers navigation, element interaction, data extraction, form filling, multi-step flows, and session management via MCP tools.
azure-messaging-webpubsub-java
Build real-time web applications with Azure Web PubSub SDK for Java. Use when implementing WebSocket-based messaging, live updates, chat applications, or server-to-client push notifications.
google-safe-browsing
Prevent and fix Google Safe Browsing "Dangerous site" flags. Use when launching a public web app, buying/picking a domain, building a login or signup page, or when any site shows a red "Dangerous site" / "Deceptive site" warning in Chrome, Brave, Safari, Firefox, or Edge. Triggers on "dangerous site", "deceptive…