Back to skill

Security audit

Suno

Security checks for vulnerabilities and agentic risk

Overview

This Suno skill is a disclosed music-generation helper that sends prompts to selected music services and stores scoped local preferences, with privacy considerations users should understand.

Install only if you are comfortable sending prompts and lyrics to the selected music service and storing local music preferences, project records, and possibly verbatim successful prompts under ~/Clawic/data/suno/. Do not put secrets, private business ideas, or sensitive personal details in prompts you do not want retained or sent to third-party providers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (20)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · api.md (reported line 31)May include surrounding context.

Setup

  1. Sign up at aimusicapi.ai
  2. Get API key from dashboard
  3. Store securely as environment variable:
bash
export AIMUSICAPI_KEY="your-key-here"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · api.md (reported line 142)May include surrounding context.

Setup

  1. Sign up at aimusicapi.ai
  2. Get API key from dashboard
  3. Store securely as environment variable:
bash
export AIMUSICAPI_KEY="your-key-here"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api.md (reported line 45)May include surrounding context.

md
import time

API_KEY = os.environ.get("AIMUSICAPI_KEY")
BASE = "https://api.aimusicapi.ai/api/v1/sonic"
HEADERS = {"Authorization": f"Bearer {API_KEY}"}

def poll_task(task_id, timeout=300):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api.md (reported line 126)May include surrounding context.

md
import time

API_KEY = os.environ.get("AIMUSICAPI_KEY")
BASE = "https://api.aimusicapi.ai/api/v1/sonic"
HEADERS = {"Authorization": f"Bearer {API_KEY}"}

def poll_task(task_id, timeout=300):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api.md (reported line 132)May include surrounding context.

md
import time

API_KEY = os.environ.get("AIMUSICAPI_KEY")
BASE = "https://api.aimusicapi.ai/api/v1/sonic"
HEADERS = {"Authorization": f"Bearer {API_KEY}"}

def poll_task(task_id, timeout=300):

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api.md (reported line 62)May include surrounding context.

md
def generate(prompt, instrumental=False):
    """Generate a song from prompt."""
    r = requests.post(f"{BASE}/generate", 
        headers=HEADERS,
        json={
            "prompt": prompt,

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api.md (reported line 73)May include surrounding context.

md
def generate_custom(lyrics, style_tags, title):
    """Generate with custom lyrics."""
    r = requests.post(f"{BASE}/custom_generate",
        headers=HEADERS,
        json={
            "prompt": lyrics,

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api.md (reported line 86)May include surrounding context.

md
def generate_lyrics(topic):
    """Generate lyrics from topic."""
    r = requests.post(f"{BASE}/lyrics",
        headers=HEADERS,
        json={"prompt": topic})
    r.raise_for_status()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api.md (reported line 122)May include surrounding context.

songs = generate_custom(lyrics, "indie pop, dreamy", "Summer Love")

text

### cURL

```bash
# Generate

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api.md (reported line 153)May include surrounding context.

md
import time

API_KEY = os.environ.get("EVOLINK_API_KEY")
BASE = "https://api.evolink.ai/v1"
HEADERS = {"Authorization": f"Bearer {API_KEY}"}

def generate_evolink(prompt, model="suno-v4", duration=120):

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api.md (reported line 158)May include surrounding context.

md
def generate_evolink(prompt, model="suno-v4", duration=120):
    """Generate with EvoLink API."""
    r = requests.post(f"{BASE}/audios/generations",
        headers=HEADERS,
        json={
            "model": model,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document directs users to persist generated audio and verbatim prompts under a local path outside the immediate generation task, creating unnecessary retention of potentially sensitive user content. In this skill context, prompts may contain private creative ideas, personal themes, names, or copyrighted/style-sensitive material, so persistent storage increases exposure risk if the workstation, logs, or backups are later accessed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction to log successful prompts verbatim to a memory file can capture and retain sensitive user-provided text without warning. In this skill, prompts may include personal details, business ideas, brand names, or copyrighted/style references, so verbatim logging creates a clear confidentiality risk beyond the immediate task.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Persistent storage of user prompts in a shared or durable memory file increases the chance of later disclosure to other tools, users, backups, or future sessions. Because this is a creative-generation skill, the retained text may include sensitive or proprietary ideas that users do not expect to be preserved indefinitely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The recommendation to download audio immediately and save it to a local filesystem path omits any notice that the skill may write files onto the user's machine. Even though saving outputs is functionally relevant for a music-generation workflow, silent or undocumented local writes can surprise users and create privacy or disk-usage issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file instructs the agent to perform downloads, which can affect the user's filesystem, but it does not explicitly warn the user that files will be saved locally or advise confirming the destination/intent first. Under the markdown-specific missing-warning rule, behaviours affecting user data or system state should be disclosed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This file is markdown, so natural-language policy checks apply. The instruction to write lyrics in the target language and explicitly label it in the style field creates a prescriptive language requirement rather than offering the user a choice, and it is not framed as optional user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template instructs the agent to create persistent files under the user's home directory and optionally store downloaded audio, but it does not require any user-facing notice or consent before writing to local storage. While the stored content is mostly preference and project data, silent persistence can surprise users, retain sensitive creative history, and create privacy issues if the environment is shared or monitored.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill instructs the agent to persist user-successful prompt strings in a local memory file, creating unnecessary retention of user-derived content outside the immediate task flow. Even if the stored data is 'just prompts,' it may still contain sensitive preferences, copyrighted style requests, or identifying phrasing, and the persistence is not clearly essential to basic music generation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file directs the skill to record the resolved method in config.yaml, which is a file write affecting persistent user data. The document does not include any explicit user-facing warning that setup will create or modify files under ~/Clawic/data/suno/.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.