Back to skill

Security audit

Qq Music

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrow QQ Music helper for summarizing visible page information, with no executable code or hidden install behavior.

Install only if you want an agent to help summarize QQ Music pages. If you are logged in, the agent may see personal QQ Music page information visible in that browser session, so avoid using it for private account workflows, downloads, or bulk scraping.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description activates on broadly defined QQ Music-related needs, which can cause the skill to be invoked for a wide range of requests beyond the narrowly intended use cases. Over-broad activation can route user tasks into a skill with web automation capabilities unnecessarily, increasing the chance of unintended browsing, data handling, or policy-bound actions on a third-party service.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.