Back to skill

Security audit

Bumblebee

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate Spotify music-control skill, but it asks users to grant and store broader Spotify account permissions than its scripts need.

Review the Spotify OAuth scopes before installing. Prefer authorizing only playback state, current playback, recent history, and playback modification unless you specifically need playlist or library features, and store projects/spotify/.env and tokens.json with owner-only permissions. This review found no evidence of credential exfiltration, hidden shell execution, or system persistence.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SETUP.md:49
Finding

Spotify OAuth Flow Requests Permissions Beyond the Skill's Functional Requirements

Content
View full analysis

Vulnerability Details

File Location: SETUP.md:49-51
Vulnerability Type: Excessive OAuth scopes and violation of least privilege
Risk Level: Medium

Vulnerable Code Snippet:

bash
# Scopes needed for full playback + library control
SCOPES="playlist-read-private playlist-read-collaborative streaming user-modify-playback-state user-library-read user-library-modify playlist-modify-private playlist-modify-public user-read-playback-state user-read-currently-playing user-read-recently-played user-top-read"

Technical Analysis

The setup process asks users to authorize Spotify scopes that are not required by the implemented functionality. The reviewed scripts use playback control, playback and device state, currently playing information, recently played history, and Spotify search.

No reviewed code modifies the user's saved library or playlists, reads private or collaborative playlists, accesses top-item data, or implements the Spotify Web Playback SDK. Consequently, the following requested scopes exceed the Skill's demonstrated requirements:

  • playlist-read-private
  • playlist-read-collaborative
  • streaming
  • user-library-read
  • user-library-modify
  • playlist-modify-private
  • playlist-modify-public
  • user-top-read

OAuth access and refresh tokens inherit these unnecessary privileges. This expands the consequences of token disclosure or misuse even though no direct credential exfiltration was found in the reviewed code.

Attack Path

  1. The user follows SETUP.md and authorizes the complete scope list.
  2. Spotify issues a refresh token carrying both necessary playback permissions and unnecessary library, playlist, and account-data permissions.
  3. The refresh token is stored in projects/spotify/tokens.json.
  4. A malicious local process, compromised agent Skill, or other actor with access to that token obtains it.
  5. The actor exchanges the refresh token for an acce ...[truncated 990 chars]
Remediation
View remediation

Remediation Suggestions

Apply least privilege to the Spotify authorization flow:

  1. Reduce the documented scope list to the scopes used by the current implementation:
    • user-modify-playback-state
    • user-read-playback-state
    • user-read-currently-playing
    • user-read-recently-played
  2. Remove playlist, library, top-items, and streaming scopes unless corresponding functionality is implemented and clearly disclosed.
  3. Explain why each requested scope is necessary beside the authorization command.
  4. Instruct existing users to revoke the current Spotify application authorization and reauthorize it with the reduced scope set. Merely changing the documentation will not reduce privileges already attached to existing refresh tokens.
  5. Consider separating optional features into separate consent flows so that additional scopes are requested only when the user explicitly enables those features.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/lyric-engine.js:67
Finding

Spotify Refresh Tokens Are Written Without Explicit Permission Hardening

Content
View full analysis

Vulnerability Details

File Location: scripts/lyric-engine.js:67-73
Additional Locations: scripts/bumblebee.js:30-36, scripts/r2-dj.js:153-159, SETUP.md:24-38, SETUP.md:77-89
Vulnerability Type: Insecure local storage of OAuth credentials
Risk Level: Low

Vulnerable Code Snippet:

javascript
function loadTokens() {
  return JSON.parse(fs.readFileSync(TOKENS_FILE, 'utf8'));
}

function saveTokens(tokens) {
  tokens.obtained_at = new Date().toISOString();
  fs.writeFileSync(TOKENS_FILE, JSON.stringify(tokens, null, 2));
}

Equivalent token-writing logic appears in scripts/bumblebee.js and scripts/r2-dj.js. The setup guide also directs users to create .env and tokens.json, which contain a Spotify client secret and long-lived refresh token, without requiring restrictive file or directory permissions.

Technical Analysis

fs.writeFileSync is called without an explicit restrictive mode and without subsequently validating or correcting the file's permissions. For a newly created file, effective permissions depend on the process umask. For an existing file, rewriting it generally preserves its prior mode, including an insecure mode.

The stored JSON includes a Spotify refresh token. The associated .env file contains the Spotify client secret. These are persistent authentication credentials rather than non-sensitive application configuration.

This is primarily a local, multi-user-host or compromised-process risk. A secure default umask may mitigate the issue on many systems, but the Skill does not enforce or document that assumption.

Attack Path

  1. The user creates the Spotify credential directory and files as instructed.
  2. The host has a permissive umask, the files are created with overly broad permissions, or an existing tokens.json already has an insecure mode.
  3. The Skill refreshes the Spotify token and rewrites tokens.json without changing that mode.

...[truncated 867 chars]

Remediation
View remediation

Remediation Suggestions

Harden credential storage consistently across all three scripts:

  1. Create the Spotify credential directory with mode 0700.

  2. Create and maintain .env and tokens.json with mode 0600.

  3. Pass an explicit mode when writing tokens and correct the mode of existing files:

    javascript
    function saveTokens(tokens) {
      tokens.obtained_at = new Date().toISOString();
      fs.writeFileSync(
        TOKENS_FILE,
        JSON.stringify(tokens, null, 2),
        { encoding: 'utf8', mode: 0o600 }
      );
      fs.chmodSync(TOKENS_FILE, 0o600);
    }
    
  4. Add setup commands such as:

    bash
    chmod 700 projects/spotify
    chmod 600 projects/spotify/.env projects/spotify/tokens.json
    
  5. Before loading credentials, reject files that are not regular files and warn or fail when group or other permission bits are set.

  6. Avoid printing token endpoint response bodies in errors because provider responses may occasionally contain sensitive diagnostic material.

  7. Where supported by the host platform, prefer a system credential store or secret-management service over plaintext credential files.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (50)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch becomes security-relevant because the skill claims one set of behaviors while also introducing undeclared external lyric API access and local indexing/catalog persistence. Undeclared network and storage behaviors reduce informed consent and can cause data to leave the local environment or be retained unexpectedly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

This mismatch becomes security-relevant because the skill claims one set of behaviors while also introducing undeclared external lyric API access and local indexing/catalog persistence. Undeclared network and storage behaviors reduce informed consent and can cause data to leave the local environment or be retained unexpectedly.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
node scripts/lyric-engine.js search "phrase to find"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
node scripts/lyric-engine.js search "phrase to find"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
node scripts/lyric-engine.js search "phrase to find"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
node scripts/lyric-engine.js search "phrase to find"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
node scripts/lyric-engine.js search "phrase to find"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
node scripts/lyric-engine.js search "phrase to find"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
node scripts/lyric-engine.js search "phrase to find"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
node scripts/lyric-engine.js search "phrase to find"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
node scripts/lyric-engine.js search "phrase to find"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
node scripts/lyric-engine.js search "phrase to find"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
node scripts/bumblebee.js devices

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
node scripts/bumblebee.js devices

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
node scripts/bumblebee.js devices

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
node scripts/bumblebee.js devices

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

md
node scripts/r2-dj.js vibe

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
node scripts/r2-dj.js vibe

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
node scripts/r2-dj.js vibe

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

md
node scripts/r2-dj.js vibe

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
node scripts/r2-dj.js vibe

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
node scripts/r2-dj.js vibe

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
node scripts/r2-dj.js vibe

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

md
node scripts/r2-dj.js vibe

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

md
node scripts/r2-dj.js vibe

Static analysis

No suspicious patterns detected.