Back to skill

Security audit

Kuwo

Security checks for vulnerabilities and agentic risk

Overview

This is a simple instruction-only Kuwo Music skill for public music-page summaries, with limited and disclosed web-use guidance.

Safe to install for Kuwo Music public trend and playlist summaries. Use it intentionally on logged-in Kuwo pages, because the agent may read information visible in that session, and avoid using it for downloads, bulk scraping, account actions, or bypassing platform controls.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is broadly phrased as applying whenever Kuwo-related content needs to be accessed or automated, which can cause the agent to invoke this skill for generic requests beyond its intended narrow scope. Over-broad triggering increases the chance of unintended web access or automation on a third-party site, even though the rest of the skill text tries to limit use to public-page, lightweight analysis.

Static analysis

No suspicious patterns detected.