妙音AI音乐助手

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI music API helper with a simple local installer, though users should understand it sends music prompts and task data to a third-party service.

Install only if you are comfortable configuring MIAOYIN_API_TOKEN and sending your lyrics, prompts, song IDs, and music task data to ai.growingth.com. Use explicit requests for quota-consuming actions such as generation, video creation, WAV conversion, and stem separation, and avoid sending private lyrics unless you intend to share them with that service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
76% confidence
Finding
An overly broad trigger description can cause the skill to activate on ordinary conversation and send user content to an external API unexpectedly. In this skill, activation can result in transmission of user-provided lyrics, prompts, or task identifiers to a third-party music service, creating consent and privacy risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal