Music Analysis

Security checks across malware telemetry and agentic risk

Overview

This skill coherently analyzes user-selected audio locally, with ordinary cautions about local media tools and broad invocation wording.

Install this if you are comfortable letting the agent run local audio-analysis tools on files you choose. Use trusted ffmpeg, ffprobe, Python packages, and Whisper binaries/models, and keep downloaded audio, temp files, and generated reports in a dedicated workspace.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
77% confidence
Finding
The manifest uses broad trigger phrases such as 'listen to this' and 'hear the music,' which can overlap with ordinary user conversation and cause the skill to activate in contexts the user did not intend. In an agent environment with shell and file-handling behavior, ambiguous invocation increases the risk of unexpected local processing of user-provided files or URLs and expands the attack surface for prompt-trigger abuse.

VirusTotal

40/40 vendors flagged this skill as clean.

View on VirusTotal