Back to skill

Security audit

IMA AI Music & Voice Generator — Song, BGM, Background Soundtrack, Jingle, Lyrics, Beat Maker, Voiceover, Narration & Composition

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed IMA music-generation client, but it has review-worthy risks around redirecting API credentials to arbitrary servers and unsafe shell-style invocation guidance.

Review before installing. Use a limited-scope IMA key, do not pass --base-url except with trusted development credentials, and ensure the host agent invokes the Python script with an argument array rather than by concatenating user text into a shell command. Expect prompts to be sent to IMA's service and local model preferences/logs to be written under ~/.openclaw.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ima_voice_create.py:862
Finding

Arbitrary API Base URL Can Exfiltrate the Bearer Credential and User Prompt

Content
View full analysis
dict: return { "Authorization": f"Bearer {api_key}", "Content-Type": "application/json", "User-Agent": "IMA-OpenAPI-Client/Skill-1.0.2", "x-app-source": "ima_skills", "x_app_language": language, } ``` ```python url = f"{base_url}/open/v1/product/list" params = {"app": app, "platform": platform, "category": TASK_TYPE} headers = make_headers(api_key, language) logger.info(f"Query product list: category={TASK_TYPE}, app={app}, platform={platform}") try: resp = requests.get(url, params=params, headers=headers, timeout=30) ``` ```python url = f"{base_url}/open/v1/tasks/create" headers = make_headers(api_key) logger.info(f"Create task: model={model_params['model_name']}, task_type={TASK_TYPE}, " f"credit={model_params['credit']}, attribute_id={model_params['attribute_id']}") try: resp = requests.post(url, json=payload, headers=headers, timeout=30) ``` ```python url = f"{base_url}/open/v1/tasks/create" headers = make_headers(api_key) logger.info(f"Attempt {attempt_num}: attribute_id={attribute_id}, credit={credit}, params={list(candidate_params.keys())}") try: resp = requests.post(url, json=payload, headers=headers, timeout=30) ``` ```python p.add_argument("--base-url", default=DEFAULT_BASE_URL, help="API base URL") ``` ### Technical Analysis The Skill needs network access to `https://api.imastudio.c ...[truncated 2455 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:104
Finding

Documented Shell Invocation Does Not Safely Handle Dynamic Prompt and User Identifier Values

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (28)

Tainted flow: 'task_id' from os.getenv (line 963, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/ima_voice_create.py (reported line 406)May include surrounding context.

python
"Check the IMA dashboard for status."
            )

        resp = requests.post(url, json={"task_id": task_id},
                             headers=headers, timeout=30)
        resp.raise_for_status()
        data = resp.json()

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL-DETAIL.md (reported line 216)May include surrounding context.

md
**Data control:**
- ✅ **View stored data**: `cat ~/.openclaw/memory/ima_prefs.json`
- ✅ **Delete preferences**: `rm ~/.openclaw/memory/ima_prefs.json` (resets to defaults)
- ✅ **Delete logs**: `rm -rf ~/.openclaw/logs/ima_skills/` (auto-cleanup after 7 days anyway)

### ⚠️ Advanced Users: Fork & Modify

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL-DETAIL.md (reported line 217)May include surrounding context.

md
**Data control:**
- ✅ **View stored data**: `cat ~/.openclaw/memory/ima_prefs.json`
- ✅ **Delete preferences**: `rm ~/.openclaw/memory/ima_prefs.json` (resets to defaults)
- ✅ **Delete logs**: `rm -rf ~/.openclaw/logs/ima_skills/` (auto-cleanup after 7 days anyway)

### ⚠️ Advanced Users: Fork & Modify

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL-DETAIL.md (reported line 217)May include surrounding context.

md
**Data control:**
- ✅ **View stored data**: `cat ~/.openclaw/memory/ima_prefs.json`
- ✅ **Delete preferences**: `rm ~/.openclaw/memory/ima_prefs.json` (resets to defaults)
- ✅ **Delete logs**: `rm -rf ~/.openclaw/logs/ima_skills/` (auto-cleanup after 7 days anyway)

### ⚠️ Advanced Users: Fork & Modify

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL-DETAIL.md (reported line 217)May include surrounding context.

md
**Data control:**
- ✅ **View stored data**: `cat ~/.openclaw/memory/ima_prefs.json`
- ✅ **Delete preferences**: `rm ~/.openclaw/memory/ima_prefs.json` (resets to defaults)
- ✅ **Delete logs**: `rm -rf ~/.openclaw/logs/ima_skills/` (auto-cleanup after 7 days anyway)

### ⚠️ Advanced Users: Fork & Modify

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL-DETAIL.md (reported line 221)May include surrounding context.

md
### ⚠️ Advanced Users: Fork & Modify

If you need to modify this skill for your use case:
1. **Fork the repository** (don't modify the original)
2. **Update your fork** with your changes
3. **Test thoroughly** with limited API keys

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Yes, this is a clear mismatch. The declared description claims a media-generation skill for AI music, songs, BGM, and voice generation. The actual code provided is only an internal logging module with file-system access for writing and deleting log files. Those behaviors are not part of the declared user-facing purpose, and the code does not show any music/voice generation capability at all. While logging can be a supporting implementation detail, this chunk’s primary and only observed behavior is logging infrastructure, which is materially different from the declared primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description overstates the skill's functionality. The code clearly states and implements only a music-generation pipeline with TASK_TYPE fixed to 'text_to_music'. It supports querying available music models, creating tasks, retry/reflection logic, polling results, and saving model preferences. There is no dedicated voice synthesis, narration, or voiceover generation flow, no separate text-to-speech endpoint, and no evidence of standalone voice generation capability. While some declared items like music/song/BGM generation are consistent with the code, the description's inclusion of AI voice generator/voiceover generator and richer custom vocal/lyrics controls is not supported as implemented behavior. This is a material description-behavior mismatch because the declared primary capability set is broader than the actual code.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ima_voice_create.py (reported line 878)May include surrounding context.

python
args   = build_parser().parse_args()
    base   = args.base_url
    
    # Get API key from args or environment variable
    apikey = args.api_key or os.getenv("IMA_API_KEY")
    if not apikey:
        logger.error("API key is required. Use --api-key or set IMA_API_KEY environment variable")

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Earlier documentation states the bundled music-generation script has an automatic reflection mechanism that retries up to 3 times on failure. Later, the failure-handling section says music generation uses direct error handling with no reflection mechanism due to simpler parameters, which is a direct contradiction about core runtime behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL-DETAIL.md (reported line 93)May include surrounding context.

md
- Most tasks succeed on first try

2. **Attempt 2: Strict Match (Error 6009 Fix)**
   - Automatically removes unsupported parameters
   - Only keeps parameters in `credit_rules.attributes`
   - Example: Removes unsupported Suno parameters if not in model config

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill persists per-user preference data under ~/.openclaw/memory/ima_prefs.json, creating cross-session state tied to user_id. Even if limited to model preferences, persistent identifiers and history can leak usage patterns, enable unintended profiling, or cause privacy issues in shared environments.

Content

Scanner excerpt · SKILL-DETAIL.md (reported line 329)May include surrounding context.

text
4. **If not found** → use the ⭐ Recommended Default (Suno sonic-v5)

### When to Write (After Every Successful Generation)

Save the used model to `~/.openclaw/memory/ima_prefs.json` under `user_{user_id}.text_to_music`.  
See `ima-image-ai/SKILL.md` → "User Preference Memory" for the full Python write snippet.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction says to 'Match the user's language (Chinese/English)', which narrows supported languages to two locales without offering user choice or documenting a justified regional limitation. This is a natural-language policy concern because it can force a specific language/locale behavior for users outside those languages.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The skill explicitly transmits user prompts and authentication headers to an external service. Even though this is the intended function of a music-generation skill, it is still a real data-transfer security concern because prompts may contain sensitive content and the API key is sent off-host for every request.

Content

Scanner excerpt · SKILL-DETAIL.md (reported line 943)May include surrounding context.

md
"parameters":    nested_params,
        }],
    }
    r = requests.post(f"{BASE_URL}/open/v1/tasks/create", headers=HEADERS, json=body)
    r.raise_for_status()
    return r.json()["data"]["id"]

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

Polling task status sends task identifiers and authentication headers to the remote API repeatedly. This is expected operational behavior, but it still creates external dependency and metadata exposure risk if task IDs, timing, or account activity are sensitive.

Content

Scanner excerpt · SKILL-DETAIL.md (reported line 951)May include surrounding context.

md
def poll(task_id: str, interval: int = 3, timeout: int = 300) -> dict:
    deadline = time.time() + timeout
    while time.time() < deadline:
        r = requests.post(f"{BASE_URL}/open/v1/tasks/detail", headers=HEADERS, json={"task_id": task_id})
        r.raise_for_status()
        task   = r.json()["data"]
        medias = task.get("medias", [])

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares environment, filesystem write, and network capabilities but does not constrain tool scope with explicit permissions or allowed-tools. In an agent ecosystem, this weakens least-privilege boundaries and can let the skill exercise broader access than users would reasonably expect, increasing the blast radius if the skill or its downstream content is abused.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The examples and mandated UX protocol prescribe user-facing responses in Chinese, such as the success caption and acknowledgment text, but do not provide any option to match the user's preferred language. This creates a natural-language policy concern because the skill appears to enforce a specific locale rather than offering a user choice.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/ima_voice_create.py (reported line 7)May include surrounding context.

python
(version tracked in SKILL.md frontmatter)

Specialized script for music/audio generation via IMA Open API.
Handles: product list query → virtual param resolution → task create → poll status

🆕 v1.1.0 Features:
  - ✨ Reflection mechanism: Automatic error recovery with 3-layer retry strategy

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ima_voice_create.py (reported line 343)May include surrounding context.

python
f"credit={model_params['credit']}, attribute_id={model_params['attribute_id']}")

    try:
        resp = requests.post(url, json=payload, headers=headers, timeout=30)
        resp.raise_for_status()
        data = resp.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ima_voice_create.py (reported line 406)May include surrounding context.

python
f"credit={model_params['credit']}, attribute_id={model_params['attribute_id']}")

    try:
        resp = requests.post(url, json=payload, headers=headers, timeout=30)
        resp.raise_for_status()
        data = resp.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ima_voice_create.py (reported line 641)May include surrounding context.

python
f"credit={model_params['credit']}, attribute_id={model_params['attribute_id']}")

    try:
        resp = requests.post(url, json=payload, headers=headers, timeout=30)
        resp.raise_for_status()
        data = resp.json()

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains multiple hard-coded Chinese user-facing strings such as success/failure reflections and suggestions, while the CLI default language is set to English at L0860 and there is no option controlling output language. That creates a locale-policy issue because the skill effectively forces a language for parts of the user experience without explicit user choice or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script writes user preference data to local storage without notifying the user, which creates undisclosed persistence of user-associated activity. On multi-user or monitored hosts, this can leak behavioral metadata and violate user expectations around ephemeral tool use.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The security/transparency sections repeatedly assert that the skill uses only api.imastudio.com. However, the later user-facing error-handling guidance embeds links to https://www.imaclaw.ai/..., creating an intent/documentation contradiction about the domains involved in the workflow presented to users.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency specification uses a lower-bound only constraint (requests>=2.25.0), which makes builds non-reproducible and allows installation of different versions over time. This weakens supply-chain control and can result in accidentally pulling a vulnerable or incompatible release, especially in environments that do not separately lock dependencies.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
# Python dependencies for ima-ai-music-song-voice-generator skill
# Install with: pip install -r requirements.txt

requests>=2.25.0

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
SKILL-DETAIL.md:217