Back to skill

Security audit

Release

Security checks for vulnerabilities and agentic risk

Overview

This is a real music-generation skill, but its installation, token handling, and persistent device tracking need careful review before use.

Install only if you are comfortable with a cloud service receiving your song prompts, account activity, bearer token, and a persistent device-linked identifier. Do not let an agent run the README clone-and-bash command automatically; inspect or pin the installer first. Treat any Muse token as a password, avoid pasting it into shared chats, and remove ~/.muse/token and ~/.muse/device_id if you stop using the skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:586
Finding

Mandatory Promotional Output and Device-Linked Traffic Diversion

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:9
Finding

Execution of an Unpinned Mutable Remote Repository

Content
View full analysis
Remediation
View remediation
git verify-commit bash install.sh ``` ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/register.py:45
Finding

Bearer Tokens Exposed Through Command Arguments, Output, and Unprotected Plaintext Storage

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/muse_api.py:20
Finding

Persistent Machine-Derived Identifier Used in API Requests and Promotional URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (32)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explicitly instructs an AI assistant to clone a repository into /tmp and execute install.sh, which is code execution and filesystem modification beyond the stated music-creation function of the skill. In an agent-skill context, documentation that tells the agent to fetch and run shell scripts is dangerous because a model or automation pipeline may follow it blindly, enabling arbitrary command execution from untrusted content.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill also performs phone-based authentication, token verification, account lookup, and persistent credential storage, none of which are clearly disclosed by a normal music-creation description. Hidden or under-disclosed identity and credential handling increases privacy and account-takeover risk if users paste secrets into a chat-driven workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill also performs phone-based authentication, token verification, account lookup, and persistent credential storage, none of which are clearly disclosed by a normal music-creation description. Hidden or under-disclosed identity and credential handling increases privacy and account-takeover risk if users paste secrets into a chat-driven workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The installation flow tells the reader to execute a shell installer from a freshly cloned remote repository without meaningful warning about what files will be created or modified. Even though it is not a curl|bash pattern, it still results in running unreviewed remote code locally, which is unsafe in a skill ecosystem where README text may be consumed by agents as instructions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The environment-detection and auto-install behavior writes into agent-specific skill directories and adapts to multiple CLI environments, which increases the capability and reach of the installer beyond simple content generation. In context, this is more dangerous because the skill is framed for direct AI assistant installation, so agent-targeted persistence and filesystem modification are being normalized inside documentation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill invokes local Python scripts, performs networked API calls, and persists data to the filesystem, but declares no explicit tool scope or permissions boundary. In an agent environment, undeclared capabilities reduce reviewability and can let a seemingly simple music skill access network and local state in ways users and operators did not expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger definition is broad enough to activate on generic music-related requests, increasing the chance that the skill runs in contexts where the user did not intend to authorize its network calls, auth handling, or local state use. Over-broad invocation criteria are more dangerous here because this skill does more than simple text transformation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Generic trigger phrases like 'music', 'song', 'compose', 'muse', and '/muse' overlap with normal conversation and can cause accidental activation. Because the skill includes credential workflows and persistent state, accidental triggers can lead to unnecessary account prompts, link presentation, or secret-handling requests.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

The same session-persistence issue is reinforced by instructions to preserve previous generation parameters for commands like retry or style changes. In a shared or multi-tenant agent setting, retained context can be replayed or mixed across users if isolation is imperfect, leading to privacy issues and unintended actions.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
制作音乐、原创歌曲、作曲、编曲、作词、填词、
 写歌词、生成歌词、BGM、纯音乐、背景音乐、配乐、
 把文字变成歌、变成音乐、做个曲子、
 song、music、compose、make a song、write a song、muse、/muse。
---

# Muse - AI 音乐创作助手

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

The same session-persistence issue is reinforced by instructions to preserve previous generation parameters for commands like retry or style changes. In a shared or multi-tenant agent setting, retained context can be replayed or mixed across users if isolation is imperfect, leading to privacy issues and unintended actions.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
制作音乐、原创歌曲、作曲、编曲、作词、填词、
 写歌词、生成歌词、BGM、纯音乐、背景音乐、配乐、
 把文字变成歌、变成音乐、做个曲子、
 song、music、compose、make a song、write a song、muse、/muse。
---

# Muse - AI 音乐创作助手

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs persistent token handling via local storage under ~/.muse/token and asks users to paste JWT-like tokens for verification. Persistent local credential storage and chat-mediated token exchange materially increase the chance of secret leakage, reuse by other local processes, or accidental disclosure in logs and transcripts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation adds registration, login fallback, and app-redirection flows beyond the declared creative scope. While not inherently malicious, these extra flows expand data collection and can condition users to follow links and provide credentials in a context where they expected only music generation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file explicitly states that only the listed muse_api.py subcommands may be used and forbids discovering or using unlisted commands. But elsewhere it instructs calling python3 scripts/muse_api.py register-url, which is not included in the allowed list even though it is later shown in examples; this is a direct contradiction in the skill’s own guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow tells users that the token will be copied to the clipboard and asks them to paste it into chat, but it does not warn that the token is sensitive or that clipboards may be readable by other applications. This creates a realistic risk of credential exposure through clipboard snooping, chat history retention, or accidental sharing, especially because the token appears to be a long-lived authentication artifact.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide directs the skill to accept a user authentication token, verify it, and persist it to ~/.muse/token, which extends the skill's capability beyond simple music generation into credential handling. Even if intended for convenience, collecting and storing bearer-style tokens locally increases the attack surface: token theft, misuse by other local processes, and unintended reuse outside the immediate authentication flow become possible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script accepts an arbitrary --path and later uses it as the installation target, creating and populating that directory without warning about overwrite/destructive effects. In combination with upgrade and uninstall behavior, a mistaken or unsafe path can lead to overwriting or deleting unrelated user files.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 178)May include surrounding context.

sh
if [ -z "$PYTHON" ]; then
  echo "❌ 未检测到 Python,请先安装 Python 3.6+"
  echo "   Ubuntu/Debian: sudo apt install python3"
  echo "   macOS: brew install python3"
  exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 188)May include surrounding context.

sh
if [ -z "$PYTHON" ]; then
  echo "❌ 未检测到 Python,请先安装 Python 3.6+"
  echo "   Ubuntu/Debian: sudo apt install python3"
  echo "   macOS: brew install python3"
  exit 1
fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 196)May include surrounding context.

sh
# ── 部署 ──
echo "🎵 Muse Skill v$VERSION 安装中..."

mkdir -p "$DATA_DIR"

# 旧版数据迁移:~/.claude/.muse → ~/.muse
OLD_DATA_DIR="$HOME/.claude/.muse"

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 196)May include surrounding context.

sh
# ── 部署 ──
echo "🎵 Muse Skill v$VERSION 安装中..."

mkdir -p "$DATA_DIR"

# 旧版数据迁移:~/.claude/.muse → ~/.muse
OLD_DATA_DIR="$HOME/.claude/.muse"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

During upgrade, the installer unconditionally deletes the existing skill directory with rm -rf "$SKILL_DIR" before reinstalling. If the target path is wrong, customized, or unexpectedly resolves to a directory containing user data, this can cause irreversible local data loss without an explicit confirmation at the point of destruction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The final instruction tells the user to send the Chinese phrase 做首歌 to start using the skill. This imposes a specific language for invocation and does not offer an alternative language or indicate that language choice is optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

SQP-3 applies to all file types and covers language/locale policy violations in natural-language content. This file’s user-facing docstrings, help text, and error messages are consistently Chinese-only, with no opt-in or indication that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code derives a persistent device identifier from hostname, MAC-derived data, and username, then stores it under ~/.muse/device_id and sends it in every request via X-Device-Id. Even though the value is hashed, it is still a stable cross-session identifier built from sensitive host attributes and is broader than necessary for a music-generation skill, enabling tracking and correlation of a user/device over time.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The docstring claims the code does not collect privacy-sensitive data and does not track user behavior, but the implementation explicitly uses hostname, MAC-derived data, and username to compute a persistent identifier. This mismatch is security-relevant because it misleads reviewers and users about what is collected and can conceal privacy risk and tracking behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.