Back to skill

Security audit

AI-Music-Stream

Security checks for vulnerabilities and agentic risk

Overview

MuseStream is a coherent music-streaming skill, but its server can expose paid generation controls and saved library data without built-in access control.

Install only if you are comfortable running a local web server that uses your Sonauto API key and stores prompts, metadata, and audio locally. Before sharing links or exposing the port, bind it to localhost or add real authentication, rate limits, HTTPS reverse proxying, and firewall rules; do not rely on `MUSESTREAM_TOKEN` unless you implement enforcement first.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
musestream_server.py:223
Finding

Unauthenticated Network Service Exposes Billable Operations and Private Library Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
musestream_server.py:944
Finding

Stored DOM Cross-Site Scripting Through Unescaped Provider Metadata

Content
View full analysis
`${t}`).join(''); ``` ```javascript function render() { document.getElementById('songList').innerHTML = songs ...[truncated 2861 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
musestream_server.py:444
Finding

Improper Path Containment Check Permits Reading Files from Sibling Paths

Content
View full analysis
") def serve_file(filename): """Serve a saved ogg file with range support for seeking.""" fpath = os.path.realpath(os.path.join(OUTPUT_DIR, filename)) if not fpath.startswith(os.path.realpath(OUTPUT_DIR)) or not os.path.exists(fpath): return "Not found", 404 file_size = os.path.getsize(fpath) range_header = request.headers.get("Range") mime = "audio/mpeg" if fpath.endswith(".mp3") else "audio/ogg" if range_header: spec = range_header.replace("bytes=", "") start_s, _, end_s = spec.partition("-") start = int(start_s) if start_s else 0 end = int(end_s) if end_s else file_size - 1 length = end - start + 1 with open(fpath, "rb") as f: f.seek(start) data = f.read(length) resp = Response(data, status=206, mimetype=mime) resp.headers["Content-Range"] = f"bytes {start}-{end}/{file_size}" resp.headers["Accept-Ranges"] = "bytes" resp.headers["Content-Length"] = str(length) return resp return Response( open(fpath, "rb").read(), mimetype=mime, headers={ "Accept-Ranges": "bytes", "Content-Length": str(file_size) } ) ``` ### Technical Analysis The endpoint attempts to prevent path traversal by resolving the requested path and testing whether its textual representation starts with the textual output-directory path. String prefixes do not represent filesystem directory boundaries. For example: - Allowed root: `/home/user/Music/MuseStream` - Resolved attacker path: `/home/user/Music/MuseStream-private/secret` The second path starts with the first string even though it is outside the intended directory ...[truncated 1704 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
musestream_server.py:202
Finding

Unbounded Session and Generation Creation Enables Credit, Memory, Thread, and Disk Exhaustion

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (33)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

1. Check if server is running

bash
curl -s http://localhost:5001/library | python3 -m json.tool | head -5

If it returns JSON → server is up. If connection refused → start it:

bash

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

md
**2. Follow SKILL.md to build the skill**

> Read ~/.openclaw/skills/openclaw-musestream/SKILL.md

**3. Generate music**

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 113)May include surrounding context.

Generate music from a prompt

bash
curl "http://localhost:5001/start?prompt=upbeat+indie+rock+morning+energy"
# → {"url": "http://localhost:5001/player?s=abc12345", ...}

Open the returned URL in a browser. Music starts streaming immediately.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
"name":         "MyProvider",
    "register_url": "https://myprovider.com",
    "key_env":      "MYPROVIDER_API_KEY",
    "generate_url": "https://api.myprovider.com/v1/generate",
    "stream_base":  "https://api.myprovider.com/v1/stream",
    "status_url":   "https://api.myprovider.com/v1/status",
    "meta_url":     "https://api.myprovider.com/v1/songs",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

md
"name":         "MyProvider",
    "register_url": "https://myprovider.com",
    "key_env":      "MYPROVIDER_API_KEY",
    "generate_url": "https://api.myprovider.com/v1/generate",
    "stream_base":  "https://api.myprovider.com/v1/stream",
    "status_url":   "https://api.myprovider.com/v1/status",
    "meta_url":     "https://api.myprovider.com/v1/songs",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
"name":         "MyProvider",
    "register_url": "https://myprovider.com",
    "key_env":      "MYPROVIDER_API_KEY",
    "generate_url": "https://api.myprovider.com/v1/generate",
    "stream_base":  "https://api.myprovider.com/v1/stream",
    "status_url":   "https://api.myprovider.com/v1/status",
    "meta_url":     "https://api.myprovider.com/v1/songs",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

md
"name":         "MyProvider",
    "register_url": "https://myprovider.com",
    "key_env":      "MYPROVIDER_API_KEY",
    "generate_url": "https://api.myprovider.com/v1/generate",
    "stream_base":  "https://api.myprovider.com/v1/stream",
    "status_url":   "https://api.myprovider.com/v1/status",
    "meta_url":     "https://api.myprovider.com/v1/songs",

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code explicitly claims the shareable URL hides the prompt, but /start returns the prompt in JSON and /player renders it into the page via promptDisplay. This can expose sensitive user intent, mood, schedule, or other private context to anyone with the link or API access, creating a confidentiality and trust issue.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · musestream_server.py (reported line 50)May include surrounding context.

python
"name":          "Sonauto",
        "register_url":  "https://sonauto.ai",
        "key_env":       "SONAUTO_API_KEY",
        "generate_url":  "https://api.sonauto.ai/v1/generations/v3",
        "stream_base":   "https://api-stream.sonauto.ai/stream",
        "status_url":    "https://api.sonauto.ai/v1/generations/status",
        "meta_url":      "https://api.sonauto.ai/v1/generations",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · musestream_server.py (reported line 52)May include surrounding context.

python
"name":          "Sonauto",
        "register_url":  "https://sonauto.ai",
        "key_env":       "SONAUTO_API_KEY",
        "generate_url":  "https://api.sonauto.ai/v1/generations/v3",
        "stream_base":   "https://api-stream.sonauto.ai/stream",
        "status_url":    "https://api.sonauto.ai/v1/generations/status",
        "meta_url":      "https://api.sonauto.ai/v1/generations",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · musestream_server.py (reported line 53)May include surrounding context.

python
"name":          "Sonauto",
        "register_url":  "https://sonauto.ai",
        "key_env":       "SONAUTO_API_KEY",
        "generate_url":  "https://api.sonauto.ai/v1/generations/v3",
        "stream_base":   "https://api-stream.sonauto.ai/stream",
        "status_url":    "https://api.sonauto.ai/v1/generations/status",
        "meta_url":      "https://api.sonauto.ai/v1/generations",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 160)May include surrounding context.

md
#     "name":         "Udio",
    #     "register_url": "https://udio.com",
    #     "key_env":      "UDIO_API_KEY",
    #     "generate_url": "https://api.udio.com/v1/generate",
    #     "stream_base":  "https://api.udio.com/v1/stream",
    #     "status_url":   "https://api.udio.com/v1/status",
    #     "meta_url":     "https://api.udio.com/v1/songs",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 161)May include surrounding context.

md
#     "name":         "Udio",
    #     "register_url": "https://udio.com",
    #     "key_env":      "UDIO_API_KEY",
    #     "generate_url": "https://api.udio.com/v1/generate",
    #     "stream_base":  "https://api.udio.com/v1/stream",
    #     "status_url":   "https://api.udio.com/v1/status",
    #     "meta_url":     "https://api.udio.com/v1/songs",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 162)May include surrounding context.

md
#     "name":         "Udio",
    #     "register_url": "https://udio.com",
    #     "key_env":      "UDIO_API_KEY",
    #     "generate_url": "https://api.udio.com/v1/generate",
    #     "stream_base":  "https://api.udio.com/v1/stream",
    #     "status_url":   "https://api.udio.com/v1/status",
    #     "meta_url":     "https://api.udio.com/v1/songs",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 163)May include surrounding context.

md
#     "name":         "Udio",
    #     "register_url": "https://udio.com",
    #     "key_env":      "UDIO_API_KEY",
    #     "generate_url": "https://api.udio.com/v1/generate",
    #     "stream_base":  "https://api.udio.com/v1/stream",
    #     "status_url":   "https://api.udio.com/v1/status",
    #     "meta_url":     "https://api.udio.com/v1/songs",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · musestream_server.py (reported line 62)May include surrounding context.

python
#     "name":         "Udio",
    #     "register_url": "https://udio.com",
    #     "key_env":      "UDIO_API_KEY",
    #     "generate_url": "https://api.udio.com/v1/generate",
    #     "stream_base":  "https://api.udio.com/v1/stream",
    #     "status_url":   "https://api.udio.com/v1/status",
    #     "meta_url":     "https://api.udio.com/v1/songs",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · musestream_server.py (reported line 63)May include surrounding context.

python
#     "name":         "Udio",
    #     "register_url": "https://udio.com",
    #     "key_env":      "UDIO_API_KEY",
    #     "generate_url": "https://api.udio.com/v1/generate",
    #     "stream_base":  "https://api.udio.com/v1/stream",
    #     "status_url":   "https://api.udio.com/v1/status",
    #     "meta_url":     "https://api.udio.com/v1/songs",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · musestream_server.py (reported line 64)May include surrounding context.

python
#     "name":         "Udio",
    #     "register_url": "https://udio.com",
    #     "key_env":      "UDIO_API_KEY",
    #     "generate_url": "https://api.udio.com/v1/generate",
    #     "stream_base":  "https://api.udio.com/v1/stream",
    #     "status_url":   "https://api.udio.com/v1/status",
    #     "meta_url":     "https://api.udio.com/v1/songs",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · musestream_server.py (reported line 65)May include surrounding context.

python
#     "name":         "Udio",
    #     "register_url": "https://udio.com",
    #     "key_env":      "UDIO_API_KEY",
    #     "generate_url": "https://api.udio.com/v1/generate",
    #     "stream_base":  "https://api.udio.com/v1/stream",
    #     "status_url":   "https://api.udio.com/v1/status",
    #     "meta_url":     "https://api.udio.com/v1/songs",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

User prompts, including prompts built from contextual fields such as mood, destination, schedule, and notes, are sent in HTTP requests to the configured provider API. The code lacks any explicit user disclosure near the context UI or request path that this personal/contextual information will leave the local system and be processed by a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Completed songs are logged with prompts and metadata to disk, and /library exposes those prompts and details to any caller without authentication. In this skill context, prompts may encode mood, schedule, destination, or other personal context, so this creates a real privacy leak for local or network-accessible users.

Content

No source excerpt is available for this finding.

Tainted flow: 'tmp' from requests.post (line 282, network input) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · musestream_server.py (reported line 291)May include surrounding context.

python
"""Drain remaining stream to file in background and save."""
            rcv = bytes_received
            try:
                with open(tmp, "ab") as f:
                    for chunk in stream.iter_content(4096):
                        if task["stop"].is_set():
                            break

Tainted flow: 'task_id' from requests.post (line 111, network input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · musestream_server.py (reported line 324)May include surrounding context.

python
print(f"Session {session}: stopped queued task {tid}")

        try:
            r = requests.get(
                f"{_P['stream_base']}/{task_id}",
                headers={"Authorization": f"Bearer {API_KEY}", "Accept": f"audio/{ext}"},
                timeout=300, stream=True,

Tainted flow: 'tmp' from requests.post (line 282, network input) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · musestream_server.py (reported line 329)May include surrounding context.

python
headers={"Authorization": f"Bearer {API_KEY}", "Accept": f"audio/{ext}"},
                timeout=300, stream=True,
            )
            f = open(tmp, "wb")
            try:
                for chunk in r.iter_content(4096):
                    if task["stop"].is_set():

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · restart_musestream.sh (reported line 8)May include surrounding context.

sh
sleep 1

cd "$(dirname "$0")"
nohup python3 musestream_server.py > /tmp/musestream.log 2>&1 &
echo "Started musestream_server.py (PID $!)"
echo "Logs: tail -f /tmp/musestream.log"

Static analysis

No suspicious patterns detected.