Back to skill

Security audit

Release

Security checks for vulnerabilities and agentic risk

Overview

This music-generation skill appears functional, but it asks the agent to handle account tokens and persistent device identifiers in ways users should review carefully before installing.

Install only if you are comfortable with this skill using a Muse cloud service, storing an account token under ~/.muse/token, creating a persistent device ID, and showing Muse landing-page links. Avoid using custom install paths, inspect install.sh before running it, and treat pasted tokens as credentials that could grant access to the Muse account if exposed in logs or local files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:588
Finding

Mandatory Promotional Tracking Link Alters Agent Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:72
Finding

User-Controlled Values Are Interpolated into Shell Commands

Content
View full analysis
Remediation
View remediation

other

Error
Location
scripts/muse_api.py:21
Finding

Stable Hardware-Derived Device Fingerprint Is Persisted and Transmitted

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/muse_api.py:54
Finding

Bearer Token Is Stored Without Explicit Permissions and Printed in Full

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:7
Finding

Installation Instructions Execute Mutable Remote Repository Content

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
install.sh:72
Finding

Arbitrary Custom Installation Path Can Be Recursively Deleted

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is framed as music creation, but it also handles user registration, phone/SMS login flows, account data retrieval, and token persistence. Expanding a creative tool into credential and identity handling increases privacy and account-takeover risk, especially when users may not expect the skill to collect or process authentication artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is framed as music creation, but it also handles user registration, phone/SMS login flows, account data retrieval, and token persistence. Expanding a creative tool into credential and identity handling increases privacy and account-takeover risk, especially when users may not expect the skill to collect or process authentication artifacts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to recognize bearer tokens pasted by the user, verify them, and persist them under ~/.muse/token. Having a conversational skill collect and store bearer tokens is dangerous because token leakage, mishandling, or reuse could directly compromise the user's account.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

During upgrade, the script unconditionally runs rm -rf on SKILL_DIR after allowing the user to set an arbitrary --path. If a user mistypes a custom path or points it at an existing directory with unrelated contents, the installer will recursively destroy that directory without warning or path safety checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explicitly instructs an AI assistant to clone a repository into /tmp and execute install.sh, which performs filesystem changes and likely installs files into agent skill directories. In the context of an agent-installable skill, this is dangerous because the document is trying to induce automated execution of repository-supplied code before the user can review it, and the safety claims in the README do not reduce that risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents use of local Python scripts, persistent token storage, and networked API access, yet declares no explicit tool scope or allowed-tools boundary. Without a restrictive manifest, an agent may be granted broader execution and file/network access than users would reasonably expect from a music-creation skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad terms like music, song, compose, and muse, which can cause accidental activation in unrelated conversations. Because this skill can perform networked actions and credential-related flows, over-triggering increases the chance of unintended data handling or confusing users into an auth flow they did not ask for.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
69% confidence
Finding

This appears to duplicate the same session-persistence concern: the skill maintains reusable context for retry and style-switch flows while also depending on locally stored tokens. In a skill with networked generation and account access, retained context can enable unintended follow-on actions without fresh user intent.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
制作音乐、原创歌曲、作曲、编曲、作词、填词、
 写歌词、生成歌词、BGM、纯音乐、背景音乐、配乐、
 把文字变成歌、变成音乐、做个曲子、
 song、music、compose、make a song、write a song、muse、/muse。
---

# Muse - AI 音乐创作助手

Session Persistence

Medium
Category
Rogue Agent
Confidence
69% confidence
Finding

This appears to duplicate the same session-persistence concern: the skill maintains reusable context for retry and style-switch flows while also depending on locally stored tokens. In a skill with networked generation and account access, retained context can enable unintended follow-on actions without fresh user intent.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
制作音乐、原创歌曲、作曲、编曲、作词、填词、
 写歌词、生成歌词、BGM、纯音乐、背景音乐、配乐、
 把文字变成歌、变成音乐、做个曲子、
 song、music、compose、make a song、write a song、muse、/muse。
---

# Muse - AI 音乐创作助手

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing prompts and workflow instructions are written exclusively in Chinese, and the skill does not indicate that users may choose another language or locale. This can violate language/locale policy when a skill implicitly mandates one language without opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented registration/login and persistent token workflow exceeds the manifest's stated music-creation purpose and introduces sensitive account operations into a chat skill. This broadens the attack surface by normalizing credential-related interactions in a context where users expect only content generation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation claims only a fixed allowlist of muse_api.py subcommands may be used, but also instructs the use of an unlisted subcommand. Contradictory execution policy weakens operator trust and can be exploited to justify broader command use than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The registration flow asks users to paste a token copied from the clipboard and states that verification will automatically save it locally, but it does not provide an explicit warning, consent step, or security guidance about local credential storage. Because the token appears to be a long-lived bearer credential, mishandling or unintended disclosure could allow account access, quota abuse, or reuse by anyone with access to the local machine or logs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide explicitly instructs the agent to verify a pasted authentication token and persist it to ~/.muse/token, giving the skill credential-handling and local secret-storage behavior beyond simple music generation. This expands the trust boundary: a conversation-facing skill is collecting bearer credentials, encouraging clipboard-based token transfer, and storing them locally where other local processes or users may access them depending on host configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script deletes the target skill directory with rm -rf in both uninstall and upgrade flows. Although there are status messages indicating the action, there is no explicit confirmation step before irreversible deletion of an existing directory, which is a safety-critical file operation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 178)May include surrounding context.

sh
if [ -z "$PYTHON" ]; then
  echo "❌ 未检测到 Python,请先安装 Python 3.6+"
  echo "   Ubuntu/Debian: sudo apt install python3"
  echo "   macOS: brew install python3"
  exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 188)May include surrounding context.

sh
if [ -z "$PYTHON" ]; then
  echo "❌ 未检测到 Python,请先安装 Python 3.6+"
  echo "   Ubuntu/Debian: sudo apt install python3"
  echo "   macOS: brew install python3"
  exit 1
fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 196)May include surrounding context.

sh
# ── 部署 ──
echo "🎵 Muse Skill v$VERSION 安装中..."

mkdir -p "$DATA_DIR"

# 旧版数据迁移:~/.claude/.muse → ~/.muse
OLD_DATA_DIR="$HOME/.claude/.muse"

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 196)May include surrounding context.

sh
# ── 部署 ──
echo "🎵 Muse Skill v$VERSION 安装中..."

mkdir -p "$DATA_DIR"

# 旧版数据迁移:~/.claude/.muse → ~/.muse
OLD_DATA_DIR="$HOME/.claude/.muse"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language description is presented only in Chinese and states the skill purpose in that language, which indicates a language-specific experience without any visible opt-in or alternative locale choice in this file. Under the policy for natural-language violations, forcing a specific language without user choice can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file contains user-facing natural-language text in Chinese, beginning with the module docstring, and the CLI help and error messages throughout the file are also Chinese-only. The policy for this audit flags language/locale constraints when the skill forces a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code derives a persistent device identifier from hostname, MAC address, and username, then stores it locally and sends it in request headers. Even though it hashes the inputs, this is still a stable cross-session identifier tied to sensitive host attributes, which is unnecessary for a music-generation skill and enables tracking, correlation, and fingerprinting beyond what users would reasonably expect.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The docstring explicitly states that no private data is collected and no user behavior is tracked, but the implementation computes a persistent identifier from username, hostname, and MAC-derived information. This mismatch is dangerous because it misleads reviewers and users about privacy behavior, reducing informed consent and obscuring a tracking mechanism in a low-risk-appearing music skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring specifies Chinese output behavior ("输出 JSON 进度事件") and the file consistently hard-codes Chinese user-facing messages. Because this is a natural-language policy issue applicable to all file types, the skill appears to force a specific language without user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file implements phone-based registration, SMS code sending, login, and token verification/persistence, which is outside the manifest’s stated scope of music creation assistance. Scope expansion into identity/auth flows increases the attack surface and introduces collection of sensitive personal data and credentials without a clearly declared user-facing need in the skill metadata.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.