Back to skill

Security audit

音潮 AI 音乐创作

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent YinChao music-generation integration that discloses its API key, network use, and optional audio upload behavior.

Before installing, understand that prompts, lyrics, and any referenced audio file or public audio URL may be sent to YinChao's platform under your API key and may consume account quota or future paid usage. Only use audio you have rights to upload, and set the API key in the environment rather than pasting it into chat.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill instructs the agent to read environment variables (`YINCHAO_API_KEY`), read local reference files, and make network calls to an external platform, but it declares no permissions. This creates a permission-transparency gap: reviewers and runtime policy systems cannot accurately assess or constrain what the skill will access, increasing the risk of unintended secret exposure, local file access, or outbound data transfer.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.