Netease Music

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a NetEase Cloud Music helper with no evidence of hidden, destructive, or credential-stealing behavior, though its trigger wording may be broader than ideal.

Install only if you want an assistant to help with NetEase Cloud Music tasks. Confirm before any browsing, repeated page visits, or actions involving a logged-in account, and do not share private account details unless the skill clearly needs them and you trust the publisher.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description is broad enough to trigger on general requests involving NetEase Cloud Music content or automation, which can cause the agent to invoke this skill outside the user's precise intent. In a browsing/automation context, overly broad routing increases the chance of unnecessary site access, data handling, or unexpected automation against a third-party service.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal