Back to skill

Security audit

Goodrp

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, coherent integration for reading currently playing Windows media and optionally showing it on Discord, with no artifact evidence of hidden or malicious behavior.

Install only if you trust the external GoodRP application and want an agent to read your currently playing media. Be especially careful with auto-show, because it can keep displaying future songs or videos on Discord until you turn it off.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill advertises activation for broad prompts like generic media questions, which can cause an agent to invoke local media-detection capabilities in situations where the user only wanted conversational help. Because the tool reads currently playing media and can lead into Discord sharing actions, over-broad routing increases the chance of unintended privacy-sensitive access or disclosure.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The auto-show workflow enables automatic posting of current media to Discord without a prominent privacy warning about ongoing disclosure of listening/viewing activity. This is dangerous because users may not realize that future media, including sensitive or embarrassing content, could be continuously exposed to Discord contacts until the feature is disabled.

Static analysis

No suspicious patterns detected.