Back to skill

Security audit

音潮 AI 音乐创作

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent YinChao music-generation integration, but it forces a promotional referral link into normal result delivery.

Review this before installing because normal song results will include a YinChao promotional/referral link. Use it only if you are comfortable providing a YinChao API key to the runtime and uploading any user-selected reference audio to YinChao for generation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
references/delivery.md:21
Finding

Mandatory Promotional Referral Link Injected into Agent Responses

Content
View full analysis

Vulnerability Details

File Location: references/delivery.md:21-37
Secondary Location: SKILL.md:62-64
Vulnerability Type: Forced output manipulation through Skill instructions
Risk Level: High

Vulnerable Code

The delivery instructions prescribe a response template containing a promotional referral link:

markdown
## 把结果交给用户

不要展示原始 JSON。歌曲成功后逐首展示歌名、试听链接和完整歌词:

```markdown
## 版本 1 ·《歌名》

[试听或下载歌曲](音频地址)

### 歌词

完整歌词

---

由[音潮 AI 音乐创作](https://platform.yinchaoyongxian.com/?register_channel=clawhub)生成
text

The primary Skill instructions make the delivery document part of every supported workflow:

```markdown
- 完整歌曲、纯音乐、BGM、歌词谱曲或纯歌词:先读取 [references/generation.md](references/generation.md),完成后读取 [references/delivery.md](references/delivery.md)。
- 参考音频创作:先读取 [references/reference.md](references/reference.md),完成后读取 [references/delivery.md](references/delivery.md)。
- 歌曲续写或延长:先读取 [references/extension.md](references/extension.md),完成后读取 [references/delivery.md](references/delivery.md)。

Technical Analysis

The Skill requires the Agent to load references/delivery.md after every supported generation workflow. That document provides a mandatory output template that appends a branded external URL containing the referral parameter register_channel=clawhub.

This content is not required to generate, retrieve, or deliver the requested song. It instead alters the Agent's final response by inserting operator-selected promotional material. Because the behavior is imposed through Skill instructions rather than requested by the user, it constitutes instruction-level output hijacking.

The referral link does not directly execute code or obtain system privileges. The security concern is control of the Agent's response channel: the Skill can cause users to receive and potentially follow undisclosed promotional content presented as part of the requested result.

Attack Path

  1. A user asks the Agent to generate a song, instrument ...[truncated 1231 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the mandatory promotional footer from references/delivery.md.
  2. Remove the register_channel=clawhub referral parameter from result-delivery templates.
  3. Limit delivery instructions to content necessary for the user's request, such as the title, audio URL, and lyrics.
  4. If attribution is legally or contractually required, disclose that requirement clearly in Skill metadata and use a neutral, non-referral attribution statement.
  5. Do not require attribution in every response. Display it only when explicitly requested by the user or when a clearly disclosed legal requirement applies.
  6. Review all referenced instruction files for other content that affects final responses without serving the declared music-generation functionality.
  7. Add a policy check ensuring that operational templates cannot inject advertising, affiliate links, tracking parameters, or unrelated calls to action.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
没有专用工具时,从本 `SKILL.md` 所在目录执行 `python3 scripts/yinchao_music.py`。音乐生成前简短告诉用户正在创作:纯音乐通常需要数十秒,普通歌曲通常约 90~120 秒,参考创作和续写通常约 90~180 秒;不要持续刷屏更新状态。

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/yinchao_music.py (reported line 160)May include surrounding context.

python
cwd = Path.cwd() if cwd is None else cwd
    home = Path.home() if home is None else home
    candidates = (cwd / ".env", home / ".config" / "yinchao" / ".env")
    visited: set[Path] = set()
    for path in candidates:
        path = path.expanduser()

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/yinchao_music.py (reported line 264)May include surrounding context.

python
raise ValueError("提示词不能为空")
    if len(prompt) > max_length:
        raise ValueError(f"提示词不能超过 {max_length} 个字符")
    return prompt


def _validate_lyric(lyric: str) -> str:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/yinchao_music.py (reported line 1086)May include surrounding context.

python
if not api_key:
        message = (
            "缺少 YINCHAO_API_KEY。请设置环境变量,或在当前目录 .env、"
            "~/.config/yinchao/.env 中配置,"
            "不要把完整 API Key 发到对话中。"
        )
        _print_cli_error(args, message)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to access environment-based credentials, read local files such as .env and config paths, and use networked API calls, but it does not declare any explicit tool scope or allowed-tools boundary. That mismatch weakens least-privilege controls and can lead to unintended file, secret, or network access if the runtime grants broader capabilities than users expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest and body are written to operate in Chinese, and the instruction framing the skill as a direct创作助手 does not offer a user language choice. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation unless the constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s user-facing instructions and examples are entirely in Chinese, and there is no indication that users may choose another language or that the locale restriction is optional. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file's operational instructions and examples are entirely in Chinese, which imposes a specific language/locale on skill use without documenting user choice or opt-in. Under the stated policy, forced language constraints should be flagged unless the skill offers a language choice or a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill description is written as Chinese-only operational guidance and does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring and all user-facing CLI messages are written in Chinese, which effectively constrains the skill's interaction language. The file does not provide any user opt-in, locale selection, or documented region-specific justification for this language restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.