Back to skill

Security audit

Lu Music Player

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a straightforward Mopidy music helper, but it includes unsafe NAS administration guidance that could weaken file permissions if followed.

Review this before installing on a shared NAS. Avoid running the chmod -R 777 command; use owner/group-specific permissions for the Mopidy container instead. Treat restart and scan commands as administrative actions that should be run only when you intend to affect that Mopidy service.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:106
Finding

World-Writable Permissions Applied Recursively to the Music Library

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 106
Vulnerability Type: Unsafe recursive filesystem permissions
Risk Level: Medium

Vulnerable Code Snippet:

bash
chmod -R 777 /vol1/1000/Docker/music-player/music/

Technical Analysis

The troubleshooting documentation instructs users to recursively apply mode 777 to the entire music library. This grants read, write, and execute permissions to the owner, group, and every other local user.

Recursive application also changes every nested file and directory. Consequently, unrelated local accounts and compromised services can modify or delete library content. Files unnecessarily receive execute permission as well. The instruction violates least-privilege principles and is particularly unsafe on a multi-user NAS.

This command is documented rather than executed automatically, so exploitation requires an administrator or sufficiently privileged user to follow the instruction.

Attack Path

  1. A privileged user follows the troubleshooting instruction and runs the documented command.
  2. The music directory and all existing nested content become world-writable.
  3. An untrusted local account or compromised low-privileged service accesses the directory.
  4. The attacker replaces, deletes, or adds media files and other content.
  5. Mopidy or another process subsequently reads, indexes, or processes the attacker-controlled content.

Impact Assessment

Exploitation does not directly grant root privileges. It grants any local account or process the ability to alter the complete music-library tree after the command has been applied. This can result in loss of integrity and availability, unauthorized content insertion, library corruption, and potential exposure to malicious files processed by Mopidy or associated media tooling.

The affected scope is /vol1/1000/Docker/music-player/music/ and all descendants present when the recursive command is ...[truncated 9 chars]

Remediation
View remediation

Remediation Suggestions

Remove the chmod -R 777 recommendation and configure ownership around the actual Mopidy service account and group.

  1. Determine the UID and GID used by Mopidy inside the container.
  2. Assign the music directory to an appropriate trusted owner and Mopidy-accessible group.
  3. Grant only the permissions required by the deployment. For a read-only library, use directory mode 750 and file mode 640, adjusted as necessary for the actual owner and group.
  4. If Mopidy must write metadata or generated content, grant group write access only to the specific directories that require it rather than to the complete library.
  5. Set directory and file modes separately instead of recursively applying one mode:
    bash
    find /vol1/1000/Docker/music-player/music/ -type d -exec chmod 750 {} \;
    find /vol1/1000/Docker/music-player/music/ -type f -exec chmod 640 {} \;
    
  6. Document backup and permission-verification steps before changing an existing library.
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The recommendation to run 'chmod -R 777' recursively makes the music directory world-readable, world-writable, and world-executable, which is an excessively permissive fix. On a NAS or shared host, this can allow unintended modification, deletion, or tampering with media files and may weaken the security posture of adjacent services that access that path.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
### 无法播放本地音乐
1. 确保音乐文件在 `/vol1/1000/Docker/music-player/music/` 目录
2. 在 Iris 界面扫描:Settings → Local Music → Scan
3. 检查文件权限:`chmod -R 777 /vol1/1000/Docker/music-player/music/`

## 作者

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad everyday music terms such as '播放音乐', '暂停音乐', and '音量', which can cause the skill to activate when the user did not intend to manage this specific Mopidy instance. Because the skill exposes infrastructure-specific endpoints and administrative guidance, unintended activation could lead users toward sensitive internal services or operational actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill includes operational commands such as container restart, log inspection, and library scan without caution text or approval boundaries. Even though the file is documentation, presenting system-affecting commands as routine steps can normalize unsafe execution and increase the chance of accidental service disruption or misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest sets the skill language to "zh-CN", and the description is also written in Chinese, which indicates the skill is constrained to a specific language/locale. Under the policy, a forced language choice should either be optional for the user or clearly justified as region-specific; neither is documented here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description, triggers, and usage examples are entirely in Chinese, which effectively forces a specific language for invocation and use. There is no indication that users may interact in another language or that the locale restriction is intentional and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.