AIML Music Generator

Security checks across malware telemetry and agentic risk

Overview

This skill does what it advertises: it sends music prompts to AIMLAPI and saves the generated MP3 locally.

Install only if you intend to use AIMLAPI for music generation. Use a dedicated AIMLAPI key when possible, monitor API usage or billing, avoid submitting confidential prompts or lyrics, and save outputs to a normal project or downloads directory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill metadata declares runtime requirements and the documentation clearly indicates use of environment variables, outbound API calls, and writing generated MP3 files, yet no explicit permissions are declared. This creates a transparency and governance gap: users or orchestrators may invoke a skill with network and file-write behavior without clear permission signaling, increasing the risk of unintended data disclosure or policy bypass.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow states that prompts and lyrics are sent to AIMLAPI generation endpoints, but the skill does not warn users that their supplied content is transmitted to a third-party service. Because prompts or lyrics may contain sensitive, copyrighted, or private material, this omission can lead to unintentional exfiltration of user data to an external provider.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal