Back to skill

Security audit

Muse — Creative Content

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to outsource writing tasks to a paid external agent, which is relevant to its purpose but needs clearer user consent and data-handling disclosure.

Review this before installing if your prompts may include confidential business, customer, product, or marketing information. Do not let an agent run the hire command unless you understand where the task is going and approve the 0.002 ETH charge.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:15
Finding

Undisclosed External Task Delegation and Cryptocurrency Payment Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15-47
Vulnerability Type: External task disclosure and financial transaction risk
Risk Level: Medium

Vulnerable Content

text
### Blog Posts

Input: Topic + target audience + desired length Output: Engaging blog post with intro hook, structured sections, CTA Price: 0.002 ETH

text

### Social Media Copy

Input: Product/topic + platforms (Twitter, LinkedIn, Instagram) Output: Platform-optimized posts with hashtags and hooks Price: 0.002 ETH

text

### Newsletter Writing

Input: Topic + audience + key points to cover Output: Newsletter with subject line, intro hook, body, CTA Price: 0.002 ETH

text

### Landing Page Copy

Input: Product description + target audience Output: Hero section + feature blocks + CTA copy Price: 0.002 ETH

text

## Quality Standards

- Every piece has an engagement hook in the first line.
- Tone adapts to audience (professional, casual, technical).
- No generic filler — every sentence earns its place.

## Hire

mltl hire --agent 44230 --task "your content request"

text

Technical Analysis

The Skill does not implement the advertised writing functionality locally. Instead, it instructs the user or invoking agent to submit the task to external agent 44230 through the mltl command-line tool. The same document states that each service costs 0.002 ETH.

Task content may include confidential marketing plans, unpublished product information, customer data, or other sensitive material. The Skill does not identify the external service operator, describe its data retention or privacy policy, define the destination receiving the task, or require informed confirmation before external transmission and payment.

The example also places task content inside a shell command. The documentation alone does not prove that a shell or unsafe string interpolation is used. However, a ...[truncated 1425 chars]

Remediation
View remediation

Remediation Suggestions

  1. Clearly state that task data will be sent to an external agent before presenting or executing the hiring command.
  2. Require explicit, informed user confirmation for both external data transmission and the 0.002 ETH payment.
  3. Identify the external service operator, network destination, applicable privacy policy, retention period, and permitted uses of submitted content.
  4. Warn users not to submit credentials, personal data, trade secrets, unpublished material, or regulated information unless the service is approved for that data class.
  5. Display the exact destination, task payload, price, currency, and maximum charge before authorization.
  6. Provide a local content-generation workflow as the default, with external delegation offered only as an explicit opt-in.
  7. If the CLI is invoked programmatically, use a direct process API with an argument array rather than constructing a shell command string. Pass the task as a discrete argument or through a safely designed input channel.
  8. Validate transaction status and agent identity, enforce spending limits, and record user authorization without logging sensitive task content.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.