Back to skill

Security audit

Giggle Generation Music

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do what it says: send music prompts to giggle.pro and return generated audio links, with some privacy and supply-chain caveats.

Install only if you are comfortable sending prompts, lyrics, titles, and style instructions to giggle.pro. Treat returned signed audio URLs like private download links, because anyone with the full link may be able to access the generated audio. Prefer running it in a restricted environment that exposes only GIGGLE_API_KEY, and consider pinning dependencies before production use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:4
Finding

Unbounded Third-Party Dependency Allows Unreviewed Package Versions

Content
View full analysis
=2.31.0 ``` The comments above are translated for clarity. The security-relevant dependency declaration is: ```text requests>=2.31.0 ``` ### Technical Analysis The project specifies only a minimum acceptable version of `requests`. It does not pin an exact audited release, provide a lockfile, or require package integrity hashes. Package installation can therefore resolve to any current or future version satisfying the constraint. This makes the installed application materially different from the source reviewed during this audit. If the package distribution channel, maintainer account, or a future compatible release is compromised, malicious code could be installed and imported into the Agent process. The dependency is imported by `scripts/giggle_music_api.py`, so code in the resolved package executes in the same Python environment and under the same operating-system identity as the Skill. The dependency may consequently inherit access to environment variables and process-level resources available to the Skill. This finding is a supply-chain hardening issue. The audit found no evidence that the current `requests` package is malicious. ### Attack Path 1. An attacker compromises the package publisher, release process, package-index account, or another component involved in dependency distribution. 2. The attacker publishes a malicious or compromised `requests` version greater than or equal to `2.31.0`. 3. The Skill is installed or rebuilt after that release becomes available. 4. The package resolver accepts the malicious version because it satisfies `requests>=2.31.0`. 5. The Skill imports `requests` while running `scripts/giggle_music_api.py`. 6. Malicious depende ...[truncated 914 chars]
Remediation
View remediation
``` 2. Generate and commit a dependency lockfile that includes the complete transitive dependency graph. 3. Require cryptographic hashes during installation, such as through a hash-pinned requirements file and: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 4. Review and test dependency updates before changing the pinned version. Use automated vulnerability scanning, but do not automatically deploy newly released versions without validation. 5. Install packages only from explicitly approved package indexes over authenticated TLS connections. 6. Run the Skill in a restricted environment with only the required environment variable, minimal filesystem permissions, and network access limited to the declared `https://giggle.pro` service where feasible. 7. Avoid exposing unrelated credentials or sensitive environment variables to the Skill process so that a compromised dependency has a smaller accessible scope. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (10)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
98% confidence
Finding

The skill explicitly instructs the agent to forward full signed asset URLs containing Policy, Key-Pair-Id, and Signature parameters directly to the user. These signed links are bearer-style access tokens; exposing them without controls can enable unintended sharing, replay, or access to generated audio by anyone who obtains the URL.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
| Plain text with error | Forward to user as-is |
| JSON `{"status": "processing", "task_id": "..."}` | Tell user "Still in progress, please ask again in a moment" |

**Link return rule**: Audio links in stdout must be **full signed URLs** (with Policy, Key-Pair-Id, Signature query params). Correct: `https://assets.giggle.pro/...?Policy=...&Key-Pair-Id=...&Signature=...`. Keep as-is when forwarding.

---

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes Python, reads a system API key, and makes external network requests, but it does not declare an explicit tool/permission scope. This weakens sandboxing and reviewability because an agent may execute code with broader capabilities than a user or platform expects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes broad phrases like 'compose', 'create music', 'background music', and 'beats', which can match ordinary conversation and cause accidental activation. That can lead to unintended transmission of user content to an external service or execution of code when the user did not clearly request this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill tells the agent to send prompts/lyrics to giggle.pro but does not present a user-facing warning that their text will be shared with a third-party service. Because lyrics and prompts may contain personal, copyrighted, or sensitive material, users may unknowingly disclose data externally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description includes broad trigger phrases such as creating music, writing songs, background music, instrumental, and beats, which can overlap with ordinary conversation and cause accidental invocation. In an agent setting, overbroad activation can unintentionally route user prompts to this skill, leading to unnecessary third-party API use, unintended data disclosure, or unexpected actions on the user's behalf.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explains API key handling and execution flow but does not clearly warn users that their prompts, lyrics, or descriptions will be transmitted to the third-party service giggle.pro for processing. Because this skill can send potentially sensitive creative content or personal text off-platform, the missing disclosure increases privacy and consent risk, especially if activation happens automatically.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/giggle_music_api.py (reported line 83)May include surrounding context.

python
url = f"{self.BASE_URL}{self.GENERATE_ENDPOINT}"

        try:
            response = requests.post(url, headers=self.headers, json=payload, timeout=30)
            response.raise_for_status()
            result = response.json()

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a lower bound only (requests>=2.31.0), which allows future installs to resolve to different versions over time. This weakens reproducibility and makes it harder to verify whether a deployed environment includes a vulnerable or breaking release, increasing supply-chain risk.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
# giggle-generation-music 依赖包

# HTTP 请求
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

Because requests is not pinned, the manifest does not establish which exact release will be installed, so known advisories affecting some requests versions cannot be ruled out. Even if the minimum version is safe today, future resolution or environment differences could pull in an affected version and expose HTTP-related credential leakage or TLS/request handling issues.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a skill for creating or composing music from prompts or lyrics, but does not indicate any credential-handling or environment access capability. While network use is expected for an external music API, directly reading process environment secrets is an additional capability not surfaced by the skill's stated purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.