Back to skill

Security audit

spotify-control

Security checks for vulnerabilities and agentic risk

Overview

This Spotify control skill is mostly coherent, but it has a real input-validation flaw that can turn volume or seek commands into unintended AppleScript execution.

Review or fix this skill before installing. It should validate volume as an integer from 0 to 100 and position as a non-negative finite number before invoking osascript; until then, only use it where you trust the agent and inputs passed to the wrapper.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/spotify-control.py:51
Finding

AppleScript Injection Through Unvalidated Volume and Position Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documentation instructs agents to use a Python wrapper and explicitly describes shell-style invocation, but the manifest declares no tool scope such as permissions or allowed-tools. This creates an authorization gap where an agent may invoke shell-capable behavior without an explicit least-privilege declaration, increasing the chance of unintended command execution or overly broad runtime access.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/spotify-control.py (reported line 8)May include surrounding context.

python
def run_osascript(script):
    try:
        process = subprocess.Popen(['osascript', '-e', script], stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True)
        stdout, stderr = process.communicate()
        if process.returncode != 0:
            print(f"Error: {stderr.strip()}")

Static analysis

No suspicious patterns detected.