Back to skill

Security audit

AI音乐生成歌曲写词作曲编曲演唱人声克隆翻唱伴奏分轨混音一键出歌

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed wrapper for a third-party AI music API, with expected network, API-key, billing, and optional voice/audio handling risks.

Before installing, treat this as a paid third-party API integration: use your own api.a7w.cn key, avoid exposing it in logs or shared commands, verify the API host, only upload audio you have rights and consent to process, and avoid voice cloning for impersonation or deception.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (98)

Tainted flow: 'req' from os.environ.get (line 78, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/a7w.py (reported line 80)May include surrounding context.

python
for attempt in range(RETRIES):
        req = urllib.request.Request(url, data=data, headers=headers, method=method)
        try:
            with urllib.request.urlopen(req, timeout=timeout) as resp:
                return json.loads(resp.read().decode("utf-8", "replace") or "{}")
        except urllib.error.HTTPError as exc:
            text = exc.read().decode("utf-8", "replace")

Tainted flow: 'req' from os.environ.get (line 78, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The save() function downloads an arbitrary URL and writes the response to a caller-controlled local path without validating the destination host or URL scheme. In a skill context, this creates an SSRF-style primitive and can also overwrite local files if the caller passes sensitive paths, especially because result URLs come from external services and may not always be trustworthy.

Content

Scanner excerpt · scripts/a7w.py (reported line 218)May include surrounding context.

python
if not url:
        raise A7wError("没有可下载的地址")
    req = urllib.request.Request(url, headers={"User-Agent": "a7w-skill/1.0"})
    with urllib.request.urlopen(req, timeout=300) as resp:
        data = resp.read()
    Path(path).write_bytes(data)
    return path

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
AI 翻唱、续写、混音、采样、母带重制、伴奏分离与分轨导出。含 17 种生成操作、13 个接口的完整参数表与真实计费口径。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.c

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
AI 翻唱、续写、混音、采样、母带重制、伴奏分离与分轨导出。含 17 种生成操作、13 个接口的完整参数表与真实计费口径。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.c

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api-export.md (reported line 187)May include surrounding context.

md
KEY=sk-你的key

# 1) 生成
TASK=$(curl -sS -X POST "$API/create" -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -d '{"type":"generate","custom":false,"prompt":"温暖的城市民谣,木吉他"}' \
  | python -c "import sys,json;print(json.load(sys.stdin)['data']['task_id'])")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api-export.md (reported line 187)May include surrounding context.

md
KEY=sk-你的key

# 1) 生成
TASK=$(curl -sS -X POST "$API/create" -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -d '{"type":"generate","custom":false,"prompt":"温暖的城市民谣,木吉他"}' \
  | python -c "import sys,json;print(json.load(sys.stdin)['data']['task_id'])")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api-export.md (reported line 193)May include surrounding context.

md
| python -c "import sys,json;print(json.load(sys.stdin)['data']['task_id'])")

# 2) 查结果拿 audio_id(免费)
AID=$(curl -sS -X POST "$API/query" -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" -d "{\"task_id\":\"$TASK\"}" \
  | python -c "import sys,json;print(json.load(sys.stdin)['data']['audio_id'])")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title and tagline present the skill entirely in Chinese and frame the experience as a fixed Chinese-language offering. There is no indication that users may choose another language or locale, which can violate language/locale policy when a skill implicitly forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README advertises voice cloning, persona extraction, and audio upload features without any nearby warning about consent, biometric sensitivity, retention, third-party processing, or data handling. Because voice data is highly sensitive and can enable impersonation or privacy harm, omitting explicit safeguards increases the risk that users upload other people's audio or expose their own biometric data without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The quick-start section instructs users to place an API key in an Authorization header and send requests to an external service, but it does not clearly warn that the key grants billable access and should only be sent to the intended third-party endpoint. This can lead to accidental credential exposure, misuse of paid resources, or users pasting secrets into untrusted contexts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 86)May include surrounding context.

python3 scripts/a7w.py schema music_generation

3. 生成一首歌(异步任务自动轮询到结束)

python3 scripts/a7w.py call music_generation create
--body '{"type":"generate","custom":false,"prompt":"一首轻快的城市清晨民谣,木吉他,温暖男声"}'

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 86)May include surrounding context.

python3 scripts/a7w.py schema music_generation

3. 生成一首歌(异步任务自动轮询到结束)

python3 scripts/a7w.py call music_generation create
--body '{"type":"generate","custom":false,"prompt":"一首轻快的城市清晨民谣,木吉他,温暖男声"}'

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
77% confidence
Finding

The README invites users to contact a WeChat account to receive an API key and runnable examples, which bypasses normal credential issuance controls and encourages out-of-band secret distribution. Sharing API keys through personal messaging channels increases the risk of unauthorized account access, poor auditing, uncontrolled reuse, and social-engineering abuse.

Content

Scanner excerpt · README.md (reported line 147)May include surrounding context.

md
## 联系我们

- **技术微信:9872659** —— 加好友时说一下是从哪个 Skill 找过来的,直接给你配套的 API Key 与能跑的示例。
- **要算力 / 要 API Key**:[算力集市 · 注册领 API Key](https://api.a7w.cn/)

---

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises and instructs use of sensitive capabilities including environment-variable access, local file read/write, network calls, and shell execution, but does not declare restrictive tool scope in machine-readable metadata. This creates a governance gap: a host agent may grant broader capabilities than users expect, increasing the chance of unauthorized data access or command execution if the skill is invoked automatically.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The top-level description is written as a broad marketing pitch and does not clearly constrain when the skill should be invoked. In agent ecosystems, ambiguous trigger language can cause over-invocation, leading the agent to send prompts, audio, or credentials to the external service in situations where the user did not explicitly request this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description prominently markets voice cloning and uploading voice audio but does not place a clear, front-loaded privacy and consent warning in the skill summary area. Because voice data is biometric/sensitive and cloning can facilitate impersonation, weak disclosure materially increases misuse risk and uninformed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README opener uses everyday language like 'give one sentence, get a complete song' without clear invocation constraints or consent gating. In an autonomous or semi-autonomous agent setting, this can encourage accidental activation and external transmission of user-supplied creative text or audio.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This section instructs direct transmission of user prompts and an API bearer token to an external third-party endpoint. External transmission is expected for this skill's function, but it is still security-relevant because user content, generated assets, and credentials leave the local environment and could be exposed through logs, misconfiguration, or unintended invocation.

Content

Scanner excerpt · SKILL.md (reported line 246)May include surrounding context.

--body '{"type":"generate","prompt":"一首轻快的城市清晨民谣,木吉他,男声","custom":false}'

text

### 直接 curl

```bash
# 提交生成任务

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This example performs a real POST request to a third-party API using a bearer token, transmitting user prompts externally. In the context of an agent skill, such examples can normalize direct credential handling and may lead to accidental disclosure through shell history, logs, or over-broad execution environments.

Content

Scanner excerpt · SKILL.md (reported line 250)May include surrounding context.

bash
# 提交生成任务
curl -sS -X POST "https://api.a7w.cn/api/v1/apps/music_generation/create" \
  -H "Authorization: Bearer $A7W_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"type":"generate","prompt":"一首轻快的城市清晨民谣,木吉他,男声","custom":false}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

Polling the external query endpoint continues the external transfer pattern and may expose task identifiers and generated asset metadata to the provider. Although operationally necessary, it is still a genuine privacy/billing concern if invocation occurs without explicit user intent.

Content

Scanner excerpt · SKILL.md (reported line 256)May include surrounding context.

md
-d '{"type":"generate","prompt":"一首轻快的城市清晨民谣,木吉他,男声","custom":false}'

# 拿返回的 task_id 查结果
curl -sS -X POST "https://api.a7w.cn/api/v1/apps/music_generation/query" \
  -H "Authorization: Bearer $A7W_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"task_id":"<上一步返回的 task_id>"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This section defines a reusable API base URL and then demonstrates multiple transmissions of lyrics, styles, audio references, and identifiers to the third-party service. The concentration of upload/generation/export flows increases the exposure surface, especially when voice and copyrighted source material may be involved.

Content

Scanner excerpt · SKILL.md (reported line 279)May include surrounding context.

bash
KEY=sk-你的key
API=https://api.a7w.cn/api/v1/apps/music_generation

# ① 写词(0.12 元)—— 也可以自己写,跳过这步
curl -sS -X POST "$API/lyrics" -H "Authorization: Bearer $KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The workflow sends lyrics, style prompts, and possibly user-provided content to an external API for processing. While consistent with the skill's purpose, it remains a true data-transfer risk because creative content and metadata may be sensitive, billable, or subject to copyright/privacy constraints.

Content

Scanner excerpt · SKILL.md (reported line 282)May include surrounding context.

md
API=https://api.a7w.cn/api/v1/apps/music_generation

# ① 写词(0.12 元)—— 也可以自己写,跳过这步
curl -sS -X POST "$API/lyrics" -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -d '{"prompt":"写一首关于凌晨加班后骑车回家的城市民谣,副歌要有希望感"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation instructs users to provide public reference audio URLs and an HTTPS callback endpoint, which causes user-supplied audio and task metadata to be transmitted to a third-party service without any privacy warning or consent guidance. In this skill’s context, uploaded audio may contain copyrighted or biometric voice data, so omission of disclosure increases the risk of unintended data exposure and privacy harm.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-create.md (reported line 213)May include surrounding context.

请求

bash
curl -sS -X POST "https://api.a7w.cn/api/v1/apps/music_generation/query" \
  -H "Authorization: Bearer $A7W_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"task_id":"<task_id>"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-export.md (reported line 25)May include surrounding context.

请求

bash
curl -sS -X POST "https://api.a7w.cn/api/v1/apps/music_generation/query" \
  -H "Authorization: Bearer $A7W_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"task_id":"<task_id>"}'

Static analysis

No suspicious patterns detected.