Back to skill

Security audit

Ai Songwriter

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese AI songwriting skill that uses MiniMax tooling for research, lyric validation, music generation, and delivery, with some user-awareness notes but no evidence of malicious behavior.

Install only if you intend to use MiniMax through mmx for Chinese-focused lyric and music generation. Expect topic prompts, lyrics, and generation parameters to be sent to MiniMax, and confirm the destination before allowing generated audio to be delivered to a chat or platform.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger set contains very broad everyday phrases that can activate the skill unintentionally, causing the agent to enter a workflow that performs external search, file creation, and music generation. Over-broad activation increases the chance of accidental tool use, unintended API consumption, and execution of side-effecting actions in contexts where the user did not actually request this skill.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
95% confidence
Finding

The trigger '写歌' is extremely short and generic, making unintended activation likely in normal conversation. Because this skill can initiate searches, generate files, and send outputs, accidental invocation can lead to unnecessary external requests and unwanted side effects.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
95% confidence
Finding

The trigger '作曲' is overly broad and can match casual or ambiguous user text not intended to invoke this full skill. Given the skill's operational scope, broad matching raises the risk of accidental external actions and resource use.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
95% confidence
Finding

The trigger '谱曲' is similarly too generic for a side-effecting skill. In context, this matters more because activation can cascade into research, generation, and outbound delivery steps rather than a harmless text-only response.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The skill requires the sensitive environment variable MINIMAX_CN_API_KEY, but the markdown does not include a clear warning to users that an API credential is needed and will be used for external service calls. Because this skill sends prompts, lyrics, and related content to MiniMax services, a brief disclosure would improve user awareness of credential use and data transmission.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest presents this as a songwriting skill focused on lyric creation, rhyme validation, MiniMax invocation, and song generation workflow. GATE 0 adds a generic background-research/search capability via mmx search query, which is not clearly justified as a required core capability from the stated purpose and expands the skill into information retrieval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill includes a generic file-sending primitive using a dynamic target string, which can route generated media to arbitrary platform/chat destinations. In a skill context, that creates data exfiltration and misdelivery risk if the target is influenced by untrusted input or if the agent sends files without strong destination validation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file uses Chinese throughout, including headings and explanatory text, and does not indicate that the user can choose another language. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file is written as prescriptive content for generating a song entirely in Chinese, including fixed Chinese lyrics and prompts such as 'with Chinese national style'. Under the policy, forcing a specific language or locale without user opt-in can be a natural-language policy violation unless clearly justified as region-specific; this file does not explicitly provide such opt-in or limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.