Back to skill

Security audit

Home Music

Security checks for vulnerabilities and agentic risk

Overview

This is a local macOS music-control helper; its broad triggers and sudo install step deserve caution, but the artifacts do not show hidden, destructive, or data-stealing behavior.

Install only if you are comfortable letting this skill control Spotify and Airfoil speakers on your Mac. Prefer placing the command in a user-local bin directory instead of using the sudo /usr/local/bin symlink, and consider renaming or disabling generic triggers like stop music if accidental voice activation would be disruptive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
96% confidence
Finding

The trigger 'stop music' overlaps semantically with a common built-in stop command and natural user speech, creating a shadow-command condition. In assistant or voice-controlled environments, this can cause the skill to intercept generic stop intents and perform its own logic, leading to unintended control of Spotify/Airfoil rather than the expected platform-native stop behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad everyday-language commands such as 'party mode', 'chill music', 'house music', and 'stop music', which can be invoked accidentally during normal conversation or routed from voice interfaces. Because this skill controls playback across multiple devices and can stop audio, ambiguous triggers increase the risk of unintended actions rather than direct code execution.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
87% confidence
Finding

The documentation instructs users to run 'sudo ln -sf ... /usr/local/bin/home-music', which requires elevated privileges and creates a root-owned global command pointing to a user-writable path in the home directory. If that script is later modified, replaced, or compromised, trusted users may unknowingly execute attacker-controlled code via a globally installed command.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

chmod +x ~/clawd/skills/home-music/home-music.sh

Symlink for global access

sudo ln -sf ~/clawd/skills/home-music/home-music.sh /usr/local/bin/home-music

text

Now `home-music` works from anywhere in your terminal! 🎉

Static analysis

No suspicious patterns detected.