Back to skill

Security audit

Music Skill

Security checks for vulnerabilities and agentic risk

Overview

This music skill does what it says at a high level, but it installs and runs an unverified remote backend service and handles account cookies with limited user controls.

Review this before installing. It will download and run a third-party backend executable, leave a local service running, write files under ~/.openclaw, and may process music-service cookies. Install only if you trust the upstream backend and are comfortable managing the running process and stored files yourself.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install.sh:9
Finding

Unverified Remote Release Binary Download and Execution

Content
View full analysis
"$PORT_FILE" echo "[music] starting service on port $PORT..." nohup "$BIN" > "$LOG_FILE" 2>&1 & ``` ### Technical Analysis The installer queries the mutable GitHub `releases/latest` endpoint, obtains a release asset URL, downloads the asset, and executes the extracted binary. It does not pin an audited version or verify a cryptographic digest or trusted signature. The `file` check only confirms that the extracted file resembles an ELF or Mach-O executable. It does not establish the publisher's identity, the artifact's integrity, or whether the executable is benign. Because the effective executable can change after the Skill package has been reviewed, the downloaded release is a remote mutable payload. HTTPS protects the network connection but does not protect a ...[truncated 1415 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/install.sh:122
Finding

Archive Extraction Without Entry Path and Link Validation

Content
View full analysis
/dev/null else echo "[music] unsupported asset format: $URL" exit 1 fi FOUND="$(find "$EXTRACT_DIR" -maxdepth 5 -type f \( -name 'go-music-api' -o -path '*/go-music-api' \) | head -n 1 || true)" ``` ### Technical Analysis The release archive is extracted directly with the platform's `tar` or `unzip` utility before its entries are inspected. The script does not independently reject: - Absolute paths. - Parent-directory traversal components such as `../`. - Symbolic or hard links that resolve outside the extraction directory. - Device files or other unexpected entry types. Some modern archive utilities implement partial traversal defenses, but behavior differs by platform and utility version. The script must not rely on unspecified or inconsistent defaults when processing an untrusted release artifact. The native-executable check later in the script does not mitigate files already written during extraction. A malicious entry could affect a path outside `extract/` before the expected executable is located or validated. ### Attack Path 1. An attacker gains the ability to replace or publish the expected upstream release asset. 2. The attacker creates an archive containing an expected binary and one or more malicious traversal, absolute-path, or link-based entries. 3. The installer downloads the archive and invokes `tar` or `unzip` ...[truncated 815 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/embed_metadata.py:71
Finding

Unrestricted Retrieval of Backend-Controlled Cover URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description promises broad cross-platform music features, but the referenced behavior appears to only cover backend install/start for Linux/macOS and omits much of the advertised functionality. This mismatch is dangerous because users and orchestrators may grant trust or permissions based on the declared purpose, while the real behavior is incomplete, misleading, or different from what was reviewed.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
- On Linux or macOS, use `scripts/install.sh` and `scripts/play.sh`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
- On Linux or macOS, use `scripts/install.sh` and `scripts/play.sh`.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill handles platform account cookies and even verifies them through API calls, but provides no privacy or secret-handling warning. Cookies are sensitive authentication material; storing or transmitting them through local services can enable account takeover, unauthorized access to paid content, or leakage through logs, files, or process history if mishandled.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
80% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/play.sh (reported line 89)May include surrounding context.

sh
source = str(item.get('source', ''))
    s = 0
    for token in query.replace('/', ' ').split():
        if token and token in name:
            s += 80
        if token and token in artist:
            s += 50

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill requests or implies powerful capabilities—shell execution, network access, and filesystem reads/writes—without declaring an explicit tool scope or permission boundary. That makes it harder for a host system or reviewer to constrain behavior, and increases the risk of overbroad execution such as arbitrary installs, downloads, and file modifications beyond the user's expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs installing software, downloading audio, and writing output and cache files to user directories without any explicit warning or consent flow about filesystem changes. In this context, silent writes are risky because the skill performs persistent local changes and may overwrite files, consume storage, or leave executables and media artifacts on disk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
81% confidence
Finding

The skill intentionally caches media-related artifacts and writes embedded metadata and lyrics to persistent files in user-accessible locations. While not overtly malicious, this creates session persistence and retained data that may expose listening history, media selections, and downloaded content to other local users or later processes.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
- avoid karaoke, cover, remix, live, DJ, and instrumental variants when possible
- download the audio stream to the requested path
- reuse cached files when an equivalent file already exists
- call `scripts/embed_metadata.py` to write title, artist, album, cover art, and embedded lyrics when available

Prefer saving final media under a sendable location such as `~/.openclaw/media/`.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · docs/cookies.md (reported line 15)May include surrounding context.

bash
PORT="$(cat "$HOME/.openclaw/music/port" 2>/dev/null || echo 8080)"
curl -fsS -X POST "http://localhost:${PORT}/api/v1/system/cookies" \
  -H "Content-Type: application/json" \
  -d '{
    "netease": "MUSIC_U=xxx; __csrf=yyy;",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs users to run a local PowerShell script with -ExecutionPolicy Bypass, which disables normal script execution safeguards for that invocation and normalizes a high-risk pattern without any warning or integrity verification steps. In this skill context, the command is used to install and launch backend software downloaded from GitHub Releases, so bypassing policy increases the chance that a tampered, replaced, or locally modified script could run unchecked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code fetches data from external URLs via urllib.request.urlopen for both the lyric endpoint and cover URL. While it logs a final success JSON, there is no prior prompt, comment, or docstring warning that user-supplied URLs will be contacted over the network, which is a safety-relevant behavior for code files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The USLT frame is always written with lang="chi", regardless of the actual lyric language or user preference. This is a natural-language locale policy concern because it hard-codes a specific language setting without opt-in or explanation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/install.sh (reported line 9)May include surrounding context.

sh
LOG_FILE="$BASE_DIR/log.txt"
PID_FILE="$BASE_DIR/pid"
PORT_FILE="$BASE_DIR/port"
API_URL="https://api.github.com/repos/guohuiyuan/go-music-api/releases/latest"

mkdir -p "$BASE_DIR"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The installer creates directories under the user's home directory, downloads and installs an executable, writes PID/port/log files, and starts a background service via nohup without any explicit consent gate or clear warning at execution time. In an agent skill context, this is risky because invoking the skill can cause persistent local changes and a long-running process that a user may not expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description says the go-music-api backend can be installed and started on Linux, macOS, and Windows. In this installer, platform selection explicitly supports only Darwin and Linux, and all other platforms exit as unsupported, so the actual installation behavior does not match the claimed cross-platform scope.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

Using nohup to launch the downloaded binary creates a persistent background service that survives the invoking shell and records state in PID/port files. In an agent-driven skill, this persistence increases risk because a user may unintentionally leave a network-accessible local service running, expanding attack surface and making behavior less visible.

Content

Scanner excerpt · scripts/install.sh (reported line 170)May include surrounding context.

sh
echo "$PORT" > "$PORT_FILE"

echo "[music] starting service on port $PORT..."
nohup "$BIN" > "$LOG_FILE" 2>&1 &
PID="$!"
echo "$PID" > "$PID_FILE"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script sends the user-provided query to a local HTTP API and then requests a music stream and lyrics-related data derived from the selected song. There is no visible disclosure, prompt, or explanatory comment in this file informing the user that their query and playback selection will be transmitted over HTTP.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code writes cache metadata to ~/.openclaw/music/cache-index.json and saves or copies MP3 files to OUT_PATH and a canonical media path. The script has no confirmation prompt and no user-facing disclosure beyond a usage line, so the data-modifying behavior is not clearly surfaced within the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script calls the GitHub API and downloads a release asset, which necessarily transmits network metadata and may reveal platform-related details via the requested asset selection. There is no explicit warning in comments or user-facing text that the installer contacts external services and fetches executables from the internet.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.