Back to skill

Security audit

YouTube Music Cast

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent music-casting purpose, but it asks users to store and use a long-lived smart-home access token with weak protection and persistent local setup.

Review this before installing. Use HTTPS for Home Assistant, create a dedicated least-privileged Home Assistant account/token if possible, lock down ~/.youtube-music-cast/config.sh with strict permissions, avoid shared machines, and be aware that the skill may run a background local web server and install command-line tools globally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:614
Finding

Home Assistant Bearer Token Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:461
Finding

Long-Lived Home Assistant Token Stored in Plaintext Shell Configuration

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:765
Finding

Unpinned Third-Party Package Installation and Upgrade

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (14)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Requesting long-lived access tokens creates a durable credential exposure risk, especially because the same section presents token generation as a routine setup step without emphasizing the sensitivity. If the token leaks through local files, logs, backups, or shell history, an attacker could remotely interact with Home Assistant services.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
The wizard will ask for:
- **Home Assistant URL** — e.g., `http://homeassistant.local:8123`
- **Long-Lived Access Token** — Generate in HA → Profile → Long-Lived Access Tokens
- **Server IP** — The machine running these scripts
- **Default media player** — e.g., `media_player.bedroom_display`

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Requesting long-lived access tokens creates a durable credential exposure risk, especially because the same section presents token generation as a routine setup step without emphasizing the sensitivity. If the token leaks through local files, logs, backups, or shell history, an attacker could remotely interact with Home Assistant services.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
The wizard will ask for:
- **Home Assistant URL** — e.g., `http://homeassistant.local:8123`
- **Long-Lived Access Token** — Generate in HA → Profile → Long-Lived Access Tokens
- **Server IP** — The machine running these scripts
- **Default media player** — e.g., `media_player.bedroom_display`

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 624)May include surrounding context.

text

**Regenerate token if needed:**
HA → Profile → Scroll down → Long-Lived Access Tokens → Generate new

### Video Mode Issues

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 858)May include surrounding context.

cast-list

Remove old files

rm /tmp/youtube-music/*.mp3

text

### 5. WiFi Matters

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include very generic terms such as 'play music', 'download music', and 'youtube music', which are likely to match ordinary user requests and invoke this skill unexpectedly. Because the skill can download content, start services, and interact with Home Assistant, over-broad activation increases the chance of unintended sensitive actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The setup instructions request a Home Assistant long-lived access token but do not prominently warn users that this credential is stored locally in a shell configuration file. Users may provide a highly privileged token without understanding the persistence and exposure risk, especially on shared systems or in backups.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 410)May include surrounding context.

md
**How it works:**
1. Downloads the audio track (320K MP3 quality)
2. Downloads the album art thumbnail from YouTube
3. Uses ffmpeg to create an MP4 video with:
   - Looping album art background
   - Audio track encoded as AAC
   - Text overlay (song title and artist name) at bottom

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 434)May include surrounding context.

  • ffmpeg must be installed on your system
    bash
    # Debian/Ubuntu
    sudo apt install ffmpeg
    
    # macOS
    brew install ffmpeg
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 657)May include surrounding context.

  • ffmpeg must be installed on your system
    bash
    # Debian/Ubuntu
    sudo apt install ffmpeg
    
    # macOS
    brew install ffmpeg
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 788)May include surrounding context.

  • ffmpeg must be installed on your system
    bash
    # Debian/Ubuntu
    sudo apt install ffmpeg
    
    # macOS
    brew install ffmpeg
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 800)May include surrounding context.

  • ffmpeg must be installed on your system
    bash
    # Debian/Ubuntu
    sudo apt install ffmpeg
    
    # macOS
    brew install ffmpeg
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 637)May include surrounding context.

md
# If not found, install it
# Debian/Ubuntu
sudo apt install ffmpeg

# macOS
brew install ffmpeg

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 698)May include surrounding context.

Solution:

  • Radio mode downloads the songs but doesn't auto-play them in sequence.
  • You need to manually play each related song, or create a simple playlist script:
    bash
    # Play all radio songs in sequence
    for file in /tmp/youtube-music/radio_*.mp3; do
    

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 870)May include surrounding context.

6. Alias Commands

Add shell aliases for faster access:

bash
# Add to ~/.bashrc or ~/.zshrc
alias cs='cast-server'
alias cd='cast-download'
alias cp='cast-play'

Static analysis

No suspicious patterns detected.