T01 · Skill Instruction Hijacking
- Location
SKILL.md:586- Finding
Mandatory Promotional Output and Device-Linked Traffic Diversion
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real music-generation skill, but its installation, token handling, and persistent device tracking need careful review before use.
Install only if you are comfortable with a cloud service receiving your song prompts, account activity, bearer token, and a persistent device-linked identifier. Do not let an agent run the README clone-and-bash command automatically; inspect or pin the installer first. Treat any Muse token as a password, avoid pasting it into shared chats, and remove ~/.muse/token and ~/.muse/device_id if you stop using the skill.
SKILL.md:586Mandatory Promotional Output and Device-Linked Traffic Diversion
README.md:9Execution of an Unpinned Mutable Remote Repository
scripts/register.py:45Bearer Tokens Exposed Through Command Arguments, Output, and Unprotected Plaintext Storage
scripts/muse_api.py:20Persistent Machine-Derived Identifier Used in API Requests and Promotional URLs
The README explicitly instructs an AI assistant to clone a repository into /tmp and execute install.sh, which is code execution and filesystem modification beyond the stated music-creation function of the skill. In an agent-skill context, documentation that tells the agent to fetch and run shell scripts is dangerous because a model or automation pipeline may follow it blindly, enabling arbitrary command execution from untrusted content.
The skill also performs phone-based authentication, token verification, account lookup, and persistent credential storage, none of which are clearly disclosed by a normal music-creation description. Hidden or under-disclosed identity and credential handling increases privacy and account-takeover risk if users paste secrets into a chat-driven workflow.
The skill also performs phone-based authentication, token verification, account lookup, and persistent credential storage, none of which are clearly disclosed by a normal music-creation description. Hidden or under-disclosed identity and credential handling increases privacy and account-takeover risk if users paste secrets into a chat-driven workflow.
The installation flow tells the reader to execute a shell installer from a freshly cloned remote repository without meaningful warning about what files will be created or modified. Even though it is not a curl|bash pattern, it still results in running unreviewed remote code locally, which is unsafe in a skill ecosystem where README text may be consumed by agents as instructions.
The environment-detection and auto-install behavior writes into agent-specific skill directories and adapts to multiple CLI environments, which increases the capability and reach of the installer beyond simple content generation. In context, this is more dangerous because the skill is framed for direct AI assistant installation, so agent-targeted persistence and filesystem modification are being normalized inside documentation.
The skill invokes local Python scripts, performs networked API calls, and persists data to the filesystem, but declares no explicit tool scope or permissions boundary. In an agent environment, undeclared capabilities reduce reviewability and can let a seemingly simple music skill access network and local state in ways users and operators did not expect.
The trigger definition is broad enough to activate on generic music-related requests, increasing the chance that the skill runs in contexts where the user did not intend to authorize its network calls, auth handling, or local state use. Over-broad invocation criteria are more dangerous here because this skill does more than simple text transformation.
Generic trigger phrases like 'music', 'song', 'compose', 'muse', and '/muse' overlap with normal conversation and can cause accidental activation. Because the skill includes credential workflows and persistent state, accidental triggers can lead to unnecessary account prompts, link presentation, or secret-handling requests.
The same session-persistence issue is reinforced by instructions to preserve previous generation parameters for commands like retry or style changes. In a shared or multi-tenant agent setting, retained context can be replayed or mixed across users if isolation is imperfect, leading to privacy issues and unintended actions.
制作音乐、原创歌曲、作曲、编曲、作词、填词、
写歌词、生成歌词、BGM、纯音乐、背景音乐、配乐、
把文字变成歌、变成音乐、做个曲子、
song、music、compose、make a song、write a song、muse、/muse。
---
# Muse - AI 音乐创作助手
The same session-persistence issue is reinforced by instructions to preserve previous generation parameters for commands like retry or style changes. In a shared or multi-tenant agent setting, retained context can be replayed or mixed across users if isolation is imperfect, leading to privacy issues and unintended actions.
制作音乐、原创歌曲、作曲、编曲、作词、填词、
写歌词、生成歌词、BGM、纯音乐、背景音乐、配乐、
把文字变成歌、变成音乐、做个曲子、
song、music、compose、make a song、write a song、muse、/muse。
---
# Muse - AI 音乐创作助手
The skill instructs persistent token handling via local storage under ~/.muse/token and asks users to paste JWT-like tokens for verification. Persistent local credential storage and chat-mediated token exchange materially increase the chance of secret leakage, reuse by other local processes, or accidental disclosure in logs and transcripts.
The documentation adds registration, login fallback, and app-redirection flows beyond the declared creative scope. While not inherently malicious, these extra flows expand data collection and can condition users to follow links and provide credentials in a context where they expected only music generation.
The file explicitly states that only the listed muse_api.py subcommands may be used and forbids discovering or using unlisted commands. But elsewhere it instructs calling python3 scripts/muse_api.py register-url, which is not included in the allowed list even though it is later shown in examples; this is a direct contradiction in the skill’s own guidance.
The workflow tells users that the token will be copied to the clipboard and asks them to paste it into chat, but it does not warn that the token is sensitive or that clipboards may be readable by other applications. This creates a realistic risk of credential exposure through clipboard snooping, chat history retention, or accidental sharing, especially because the token appears to be a long-lived authentication artifact.
The guide directs the skill to accept a user authentication token, verify it, and persist it to ~/.muse/token, which extends the skill's capability beyond simple music generation into credential handling. Even if intended for convenience, collecting and storing bearer-style tokens locally increases the attack surface: token theft, misuse by other local processes, and unintended reuse outside the immediate authentication flow become possible.
The script accepts an arbitrary --path and later uses it as the installation target, creating and populating that directory without warning about overwrite/destructive effects. In combination with upgrade and uninstall behavior, a mistaken or unsafe path can lead to overwriting or deleting unrelated user files.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
if [ -z "$PYTHON" ]; then
echo "❌ 未检测到 Python,请先安装 Python 3.6+"
echo " Ubuntu/Debian: sudo apt install python3"
echo " macOS: brew install python3"
exit 1
fi
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
if [ -z "$PYTHON" ]; then
echo "❌ 未检测到 Python,请先安装 Python 3.6+"
echo " Ubuntu/Debian: sudo apt install python3"
echo " macOS: brew install python3"
exit 1
fi
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# ── 部署 ──
echo "🎵 Muse Skill v$VERSION 安装中..."
mkdir -p "$DATA_DIR"
# 旧版数据迁移:~/.claude/.muse → ~/.muse
OLD_DATA_DIR="$HOME/.claude/.muse"
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# ── 部署 ──
echo "🎵 Muse Skill v$VERSION 安装中..."
mkdir -p "$DATA_DIR"
# 旧版数据迁移:~/.claude/.muse → ~/.muse
OLD_DATA_DIR="$HOME/.claude/.muse"
During upgrade, the installer unconditionally deletes the existing skill directory with rm -rf "$SKILL_DIR" before reinstalling. If the target path is wrong, customized, or unexpectedly resolves to a directory containing user data, this can cause irreversible local data loss without an explicit confirmation at the point of destruction.
The final instruction tells the user to send the Chinese phrase 做首歌 to start using the skill. This imposes a specific language for invocation and does not offer an alternative language or indicate that language choice is optional.
SQP-3 applies to all file types and covers language/locale policy violations in natural-language content. This file’s user-facing docstrings, help text, and error messages are consistently Chinese-only, with no opt-in or indication that the skill is intentionally region-specific.
The code derives a persistent device identifier from hostname, MAC-derived data, and username, then stores it under ~/.muse/device_id and sends it in every request via X-Device-Id. Even though the value is hashed, it is still a stable cross-session identifier built from sensitive host attributes and is broader than necessary for a music-generation skill, enabling tracking and correlation of a user/device over time.
The docstring claims the code does not collect privacy-sensitive data and does not track user behavior, but the implementation explicitly uses hostname, MAC-derived data, and username to compute a persistent identifier. This mismatch is security-relevant because it misleads reviewers and users about what is collected and can conceal privacy risk and tracking behavior.
No suspicious patterns detected.