Back to skill

Security audit

AIMP-player

Security checks for vulnerabilities and agentic risk

Overview

This is a small Windows AIMP playback-control skill that can change local audio playback but does not install code, persist, or access private data.

Install only if you want Codex to control AIMP playback on your Windows machine. Review requests before running them because skip, stop, pause, and play commands take effect immediately and silently.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The heading and comment state 'close the player entirely' and 'exit the application,' but the command shown is only AIMP.exe /STOP, which matches the earlier switch reference as stopping playback only. This is a direct contradiction between the inline documentation and the demonstrated behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents commands that execute immediately and silently, including skipping tracks and stopping playback. While not destructive, these actions affect the user's current system state, and the documentation does not include a clear caution or confirmation-oriented warning beyond the factual note that commands are silent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.