Back to skill

Security audit

last.fm

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal Last.fm API helper; the main caveat is that user endpoints can reveal listening history.

Before installing, be aware that Last.fm user endpoints may expose personal listening patterns. Use it for user-directed queries, avoid unnecessary storage or sharing of retrieved profile/listening data, and confirm any API key or username use is intended.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly documents retrieval of user-specific Last.fm profile, listening history, and library data, but provides no warning about privacy implications, data minimization, or safe handling of personal listening information. While the APIs appear to access public or user-visible data rather than privileged secrets, the absence of privacy guidance increases the risk that downstream agents or users will collect, retain, or expose personal behavioral data without appropriate notice or controls.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.