Back to skill

Security audit

Apple Music

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent Apple Music guidance, but it includes under-scoped destructive music-library actions and recommends installing an unpinned third-party MCP server that would run local code.

Review carefully before installing. Use the direct AppleScript or official MusicKit examples for clearly user-requested actions, require confirmation before deleting playlists or changing library data, and avoid the optional MCP install unless you pin and inspect a specific trusted commit and limit token exposure.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:557
Finding

Unpinned Third-Party MCP Server Is Installed Directly from a Mutable Repository

Content
View full analysis
Remediation
View remediation
``` 2. Verify the checked-out commit against a trusted digest or a cryptographically signed release before installation. 3. Prefer an immutable, versioned release artifact with published SHA-256 hashes. If installing dependencies from a lock file, require exact versions and hashes. 4. Review the pinned repository's packaging metadata, build backend, installation hooks, runtime network destinations, and transitive dependencies before recommending execution. 5. Install and run the component in an isolated environment with minimum privileges. Do not run installation commands as root or with `sudo`. 6. Restrict credential exposure: - Supply Apple tokens only when MusicKit functionality is explicitly requested. - Store tokens using an operating-system credential store rather than plaintext files or environment-wide configuration. - Avoid exposing the `.p8` private key to the MCP runtime if only a generated developer token is required. - Revoke and rotate tokens if an installed version is later found to be compromised. 7. Clearly label the MCP server as an optional, externally maintained component that is outside the audited Skill package, rather than presenting direct installation from the default branch as the easy path. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documents destructive Apple Music operations such as deleting playlists and removing tracks without any guidance to require explicit user confirmation. In an agent setting, these examples can normalize or encourage direct execution of irreversible user-data changes from natural-language requests, increasing the risk of accidental data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The MusicKit workflow includes library and playlist modification examples that change user data, but it does not instruct the agent to warn the user or confirm intent before making those changes. In practice, this can lead to unauthorized or accidental additions to a user's library or playlists when the skill is invoked automatically.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.