Back to skill

Security audit

三剪客 · 音乐生成

Security checks for vulnerabilities and agentic risk

Overview

This is a real music-generation API wrapper, but it needs Review because its client can use stored API credentials with arbitrary hosts and non-music marketplace APIs.

Review this before installing if you will store a real a7w API key. Only use it with the intended api.a7w.cn host, avoid setting A7W_HOST or --host unless you fully trust the destination, and be aware that the client can call non-music a7w plugins and spend account credits. Do not upload voices, lyrics, or reference audio unless you have consent and rights to share them with the third-party service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (30)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The client allows the destination host to be overridden via command-line/config/environment and then sends the Bearer API key to that URL without validation. An attacker who can influence A7W_HOST or the saved config can redirect requests to an arbitrary server and capture the credential, turning this into SSRF plus credential exfiltration.

Content

Scanner excerpt · scripts/client.py (reported line 111)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

This duplicate sink has the same core issue: request_soft builds an authenticated request using a host that can come from environment/config and sends it with urllib.urlopen. In the dump path this can repeatedly leak the API key to an attacker-controlled endpoint while enumerating apps, increasing exposure volume.

Content

Scanner excerpt · scripts/client.py (reported line 153)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            return json.loads(resp.read().decode("utf-8", "replace")), resp.status
    except urllib.error.HTTPError as exc:
        raw = exc.read().decode("utf-8", "replace")

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented purpose is a music-generation wrapper, but the referenced behavior includes generic plugin marketplace enumeration, arbitrary plugin API invocation, local API key storage, task statistics, and schema dumping. That mismatch is dangerous because users may trust the skill with music content while it actually enables broader API access and local persistence beyond the declared scope.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
频导出和分轨处理。支持 歌词混合、人声处理、优化音乐风格、导出 MIDI、歌词时间轴、导出 MP4、导出 WAV、声音克隆。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.c

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
频导出和分轨处理。支持 歌词混合、人声处理、优化音乐风格、导出 MIDI、歌词时间轴、导出 MP4、导出 WAV、声音克隆。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.c

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises executable client capabilities including environment access, file read/write, network, and shell use, but does not declare any explicit tool scope or permissions boundaries. In practice this reduces transparency and makes it easier for a seemingly narrow music skill to perform broader local and network actions than a user would reasonably expect.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 11)May include surrounding context.

md
name: music-generation-kit
slug: music-generation-kit
displayName: 三剪客 · 音乐生成
description: "音乐生成应用,支持歌曲生成、歌词生成、参考音频、声音克隆、音频导出和分轨处理。支持 歌词混合、人声处理、优化音乐风格、导出 MIDI、歌词时间轴、导出 MP4、导出 WAV、声音克隆。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「音乐生成」的完整调用封装:13 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 95)May include surrounding context.

md
name: music-generation-kit
slug: music-generation-kit
displayName: 三剪客 · 音乐生成
description: "音乐生成应用,支持歌曲生成、歌词生成、参考音频、声音克隆、音频导出和分轨处理。支持 歌词混合、人声处理、优化音乐风格、导出 MIDI、歌词时间轴、导出 MP4、导出 WAV、声音克隆。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「音乐生成」的完整调用封装:13 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 104)May include surrounding context.

md
name: music-generation-kit
slug: music-generation-kit
displayName: 三剪客 · 音乐生成
description: "音乐生成应用,支持歌曲生成、歌词生成、参考音频、声音克隆、音频导出和分轨处理。支持 歌词混合、人声处理、优化音乐风格、导出 MIDI、歌词时间轴、导出 MP4、导出 WAV、声音克隆。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「音乐生成」的完整调用封装:13 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: music-generation-kit
slug: music-generation-kit
displayName: 三剪客 · 音乐生成
description: "音乐生成应用,支持歌曲生成、歌词生成、参考音频、声音克隆、音频导出和分轨处理。支持 歌词混合、人声处理、优化音乐风格、导出 MIDI、歌词时间轴、导出 MP4、导出 WAV、声音克隆。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「音乐生成」的完整调用封装:13 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
name: music-generation-kit
slug: music-generation-kit
displayName: 三剪客 · 音乐生成
description: "音乐生成应用,支持歌曲生成、歌词生成、参考音频、声音克隆、音频导出和分轨处理。支持 歌词混合、人声处理、优化音乐风格、导出 MIDI、歌词时间轴、导出 MP4、导出 WAV、声音克隆。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「音乐生成」的完整调用封装:13 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
name: music-generation-kit
slug: music-generation-kit
displayName: 三剪客 · 音乐生成
description: "音乐生成应用,支持歌曲生成、歌词生成、参考音频、声音克隆、音频导出和分轨处理。支持 歌词混合、人声处理、优化音乐风格、导出 MIDI、歌词时间轴、导出 MP4、导出 WAV、声音克隆。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「音乐生成」的完整调用封装:13 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not clearly warn users that lyrics, audio, and related media will be transmitted to a third-party service for processing. This creates a privacy and compliance risk because users may upload copyrighted, confidential, or personal voice content without informed consent about where it is sent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill exposes voice cloning and singer-persona creation features without a prominent warning about consent, impersonation, and identity misuse risks. In this context, omission is particularly dangerous because users may submit someone else's voice or likeness-related material without authorization, enabling fraud, harassment, or non-consensual synthetic media generation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The API documentation explicitly supports uploading or referencing user audio and sending asynchronous notifications to a caller-supplied callback_url, but it does not warn about privacy, third-party data exposure, or webhook-related trust boundaries. In this skill context, users may submit sensitive voice recordings for cloning or processing, so omission of guidance around HTTPS validation, minimization, consent, retention, and callback authentication can lead to unintentional disclosure or misuse of personal audio data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill documentation is presented only in Chinese, including operational descriptions and parameter explanations, with no indication that users may choose another language or that the locale restriction is required for a region-specific purpose. Under the policy, a forced language/locale without opt-in or clear justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file title and all user-facing documentation are presented exclusively in Chinese, which can constitute a language/locale policy issue when no opt-in or alternative language is offered. The document does not state that the API is region-specific or otherwise justified to require Chinese-only usage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs users to submit a publicly accessible audio URL but does not warn that the referenced media must be exposed to the internet and may contain sensitive or copyrighted content. In this skill context, users are likely to upload personal voice samples or reference tracks, so omission of privacy and access-scope guidance increases the risk of unintended data disclosure and third-party retention.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document describes a voice-cloning API that creates a reusable voice identity from uploaded speech, but it provides no warning or control guidance around speaker consent, impersonation risk, privacy, or rights ownership. In the context of a turnkey music-generation skill, this omission can normalize unsafe use and facilitate non-consensual cloning, fraud, harassment, or misuse of biometric voice data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is presented as a music-generation kit, but the code explicitly implements a generic client for calling any plugin in the marketplace. That capability expansion breaks least privilege and broadens what an invoking agent can do beyond the declared music-only scope, which is dangerous in agent environments that rely on metadata for trust and permission decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring, CLI descriptions, and user-facing operational guidance are written only in Chinese, which effectively forces a specific language on users without opt-in or documented locale justification. This matches the policy category for language/locale violations because the skill does not offer an alternative language or indicate that it is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

User-facing stderr/stdout messages throughout the CLI are emitted only in Chinese, including authentication errors, network failures, usage help, and progress messages. This enforces a specific locale in operational behavior rather than merely in comments, and no opt-in or documented justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill description and usage guidance are written only in Chinese, with no indication that other languages are supported or that the language choice is intentional and optional. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Natural-language policy violations include forcing a specific language without user opt-in. This file presents all user-facing documentation in Chinese and does not indicate any language selection or justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents an optional callback_url where the platform will proactively send completion or failure notifications, but it does not warn users that this causes data to be transmitted to an external HTTPS endpoint they control. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.