Back to skill

Security audit

Music Helper

Security checks for vulnerabilities and agentic risk

Overview

This music helper uses network lookups and local JSON storage in ways that fit its stated music search, lyric, cache, favorites, and playlist features.

Install only if you are comfortable with music searches and lyric/ranking lookups being sent to Netease music endpoints and with favorites, playlists, play counts, and cache data being stored as local JSON files. Review or clear those local files if music preferences are sensitive on your device.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

SQP-3 applies to all file types and covers natural-language policy violations such as forcing a specific language. This skill's documentation, examples, and interaction patterns are entirely in Chinese, with no indication that users can choose another language or that the language constraint is an intentional region-specific limitation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill requests or implies network and file read/write capabilities in its markdown, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates a trust and containment gap: the runtime may permit broader access than users or reviewers expect, increasing the risk of unintended file access or external data transmission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The title, description, trigger rules, examples, and interaction patterns are entirely in Chinese, and the skill does not indicate that users may choose another language. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are very broad and match ordinary music-related conversation, so the skill may activate when the user did not intend to use it. Unintended invocation can cause unexpected network calls, retrieval of external content, or local state changes such as playlist writes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill stores favorites and playlists on local disk, including user preference history such as saved songs and play counts, but it does not clearly notify users of this behavior. Silent local persistence can expose personal preference data to other local users, backups, or unrelated processes and may violate user expectations around privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill indicates it will contact external music and lyrics services, but it does not warn users that their queries, song interests, or lyric fragments may be transmitted to third parties. Music queries can reveal language, mood, interests, or other behavioral signals, so undisclosed sharing creates a meaningful privacy risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description, trigger examples, supported moods/scenes, and response strings are all in Chinese, with no indication that other languages are supported or that the user can choose a locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Accept-Language header is fixed to prefer zh-CN/zh, which imposes a specific locale behavior in the skill. The file also presents its user-facing descriptions and outputs in Chinese, but does not document any opt-in or configurable language selection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The markdown advertises real-time lyric lookup and later documents Netease API/crawler integration and optional self-hosted API deployment, which implies external network requests. Under SQP-2 for markdown files, the description should warn about privacy-relevant behavior when user inputs may be sent to third-party services, but no such warning is present.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This is a markdown file, so SQP-2 applies to omitted warnings about behaviors affecting user data or system state. The README notes that favorites.json and playlists.json are automatically generated and promotes 收藏管理/歌单管理 features, but it never explicitly warns users that invoking these features will create and persist local data files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code persists user music preferences to favorites.json and playlists.json on disk, which affects user data storage. The file write happens silently with only an internal docstring, and there is no visible confirmation prompt or privacy/storage warning in this file's user-facing help text.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.