clawtunes

Security checks across malware telemetry and agentic risk

Overview

This skill transparently controls Apple Music on macOS through the clawtunes CLI, with no evidence of hidden or unrelated behavior.

Install this only if you want an assistant to control Apple Music on your Mac. Be aware it can start or stop playback, change volume or AirPlay output, mark tracks liked/disliked, and create or modify playlists; request confirmation before playlist removals or output changes if those actions matter to you.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is broadly scoped to trigger on generic music-related requests such as playing music, searching for songs, controlling playback, or managing audio. Overly broad invocation boundaries can cause the agent to select this skill in unintended contexts, leading to unauthorized media control, playlist changes, volume changes, or AirPlay device switching on the user's macOS system.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal