T09 · Insecure Skill Coding Practices
- Location
musestream_server.py:223- Finding
Unauthenticated Network Service Exposes Billable Operations and Private Library Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
MuseStream is a coherent music-streaming skill, but its server can expose paid generation controls and saved library data without built-in access control.
Install only if you are comfortable running a local web server that uses your Sonauto API key and stores prompts, metadata, and audio locally. Before sharing links or exposing the port, bind it to localhost or add real authentication, rate limits, HTTPS reverse proxying, and firewall rules; do not rely on `MUSESTREAM_TOKEN` unless you implement enforcement first.
musestream_server.py:223Unauthenticated Network Service Exposes Billable Operations and Private Library Data
musestream_server.py:944Stored DOM Cross-Site Scripting Through Unescaped Provider Metadata
musestream_server.py:444Improper Path Containment Check Permits Reading Files from Sibling Paths
musestream_server.py:202Unbounded Session and Generation Creation Enables Credit, Memory, Thread, and Disk Exhaustion
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s http://localhost:5001/library | python3 -m json.tool | head -5
If it returns JSON → server is up. If connection refused → start it:
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
**2. Follow SKILL.md to build the skill**
> Read ~/.openclaw/skills/openclaw-musestream/SKILL.md
**3. Generate music**
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl "http://localhost:5001/start?prompt=upbeat+indie+rock+morning+energy"
# → {"url": "http://localhost:5001/player?s=abc12345", ...}
Open the returned URL in a browser. Music starts streaming immediately.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "MyProvider",
"register_url": "https://myprovider.com",
"key_env": "MYPROVIDER_API_KEY",
"generate_url": "https://api.myprovider.com/v1/generate",
"stream_base": "https://api.myprovider.com/v1/stream",
"status_url": "https://api.myprovider.com/v1/status",
"meta_url": "https://api.myprovider.com/v1/songs",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "MyProvider",
"register_url": "https://myprovider.com",
"key_env": "MYPROVIDER_API_KEY",
"generate_url": "https://api.myprovider.com/v1/generate",
"stream_base": "https://api.myprovider.com/v1/stream",
"status_url": "https://api.myprovider.com/v1/status",
"meta_url": "https://api.myprovider.com/v1/songs",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "MyProvider",
"register_url": "https://myprovider.com",
"key_env": "MYPROVIDER_API_KEY",
"generate_url": "https://api.myprovider.com/v1/generate",
"stream_base": "https://api.myprovider.com/v1/stream",
"status_url": "https://api.myprovider.com/v1/status",
"meta_url": "https://api.myprovider.com/v1/songs",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "MyProvider",
"register_url": "https://myprovider.com",
"key_env": "MYPROVIDER_API_KEY",
"generate_url": "https://api.myprovider.com/v1/generate",
"stream_base": "https://api.myprovider.com/v1/stream",
"status_url": "https://api.myprovider.com/v1/status",
"meta_url": "https://api.myprovider.com/v1/songs",
The code explicitly claims the shareable URL hides the prompt, but /start returns the prompt in JSON and /player renders it into the page via promptDisplay. This can expose sensitive user intent, mood, schedule, or other private context to anyone with the link or API access, creating a confidentiality and trust issue.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "Sonauto",
"register_url": "https://sonauto.ai",
"key_env": "SONAUTO_API_KEY",
"generate_url": "https://api.sonauto.ai/v1/generations/v3",
"stream_base": "https://api-stream.sonauto.ai/stream",
"status_url": "https://api.sonauto.ai/v1/generations/status",
"meta_url": "https://api.sonauto.ai/v1/generations",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "Sonauto",
"register_url": "https://sonauto.ai",
"key_env": "SONAUTO_API_KEY",
"generate_url": "https://api.sonauto.ai/v1/generations/v3",
"stream_base": "https://api-stream.sonauto.ai/stream",
"status_url": "https://api.sonauto.ai/v1/generations/status",
"meta_url": "https://api.sonauto.ai/v1/generations",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "Sonauto",
"register_url": "https://sonauto.ai",
"key_env": "SONAUTO_API_KEY",
"generate_url": "https://api.sonauto.ai/v1/generations/v3",
"stream_base": "https://api-stream.sonauto.ai/stream",
"status_url": "https://api.sonauto.ai/v1/generations/status",
"meta_url": "https://api.sonauto.ai/v1/generations",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# "name": "Udio",
# "register_url": "https://udio.com",
# "key_env": "UDIO_API_KEY",
# "generate_url": "https://api.udio.com/v1/generate",
# "stream_base": "https://api.udio.com/v1/stream",
# "status_url": "https://api.udio.com/v1/status",
# "meta_url": "https://api.udio.com/v1/songs",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# "name": "Udio",
# "register_url": "https://udio.com",
# "key_env": "UDIO_API_KEY",
# "generate_url": "https://api.udio.com/v1/generate",
# "stream_base": "https://api.udio.com/v1/stream",
# "status_url": "https://api.udio.com/v1/status",
# "meta_url": "https://api.udio.com/v1/songs",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# "name": "Udio",
# "register_url": "https://udio.com",
# "key_env": "UDIO_API_KEY",
# "generate_url": "https://api.udio.com/v1/generate",
# "stream_base": "https://api.udio.com/v1/stream",
# "status_url": "https://api.udio.com/v1/status",
# "meta_url": "https://api.udio.com/v1/songs",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# "name": "Udio",
# "register_url": "https://udio.com",
# "key_env": "UDIO_API_KEY",
# "generate_url": "https://api.udio.com/v1/generate",
# "stream_base": "https://api.udio.com/v1/stream",
# "status_url": "https://api.udio.com/v1/status",
# "meta_url": "https://api.udio.com/v1/songs",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# "name": "Udio",
# "register_url": "https://udio.com",
# "key_env": "UDIO_API_KEY",
# "generate_url": "https://api.udio.com/v1/generate",
# "stream_base": "https://api.udio.com/v1/stream",
# "status_url": "https://api.udio.com/v1/status",
# "meta_url": "https://api.udio.com/v1/songs",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# "name": "Udio",
# "register_url": "https://udio.com",
# "key_env": "UDIO_API_KEY",
# "generate_url": "https://api.udio.com/v1/generate",
# "stream_base": "https://api.udio.com/v1/stream",
# "status_url": "https://api.udio.com/v1/status",
# "meta_url": "https://api.udio.com/v1/songs",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# "name": "Udio",
# "register_url": "https://udio.com",
# "key_env": "UDIO_API_KEY",
# "generate_url": "https://api.udio.com/v1/generate",
# "stream_base": "https://api.udio.com/v1/stream",
# "status_url": "https://api.udio.com/v1/status",
# "meta_url": "https://api.udio.com/v1/songs",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# "name": "Udio",
# "register_url": "https://udio.com",
# "key_env": "UDIO_API_KEY",
# "generate_url": "https://api.udio.com/v1/generate",
# "stream_base": "https://api.udio.com/v1/stream",
# "status_url": "https://api.udio.com/v1/status",
# "meta_url": "https://api.udio.com/v1/songs",
User prompts, including prompts built from contextual fields such as mood, destination, schedule, and notes, are sent in HTTP requests to the configured provider API. The code lacks any explicit user disclosure near the context UI or request path that this personal/contextual information will leave the local system and be processed by a third-party service.
Completed songs are logged with prompts and metadata to disk, and /library exposes those prompts and details to any caller without authentication. In this skill context, prompts may encode mood, schedule, destination, or other personal context, so this creates a real privacy leak for local or network-accessible users.
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
"""Drain remaining stream to file in background and save."""
rcv = bytes_received
try:
with open(tmp, "ab") as f:
for chunk in stream.iter_content(4096):
if task["stop"].is_set():
break
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
print(f"Session {session}: stopped queued task {tid}")
try:
r = requests.get(
f"{_P['stream_base']}/{task_id}",
headers={"Authorization": f"Bearer {API_KEY}", "Accept": f"audio/{ext}"},
timeout=300, stream=True,
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
headers={"Authorization": f"Bearer {API_KEY}", "Accept": f"audio/{ext}"},
timeout=300, stream=True,
)
f = open(tmp, "wb")
try:
for chunk in r.iter_content(4096):
if task["stop"].is_set():
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
sleep 1
cd "$(dirname "$0")"
nohup python3 musestream_server.py > /tmp/musestream.log 2>&1 &
echo "Started musestream_server.py (PID $!)"
echo "Logs: tail -f /tmp/musestream.log"
No suspicious patterns detected.