Back to skill

Security audit

酷狗

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Kugou music assistant, but it should be reviewed because it uses a global npm CLI, can solicit and store account secrets, and accesses or changes personal music account data.

Install only if you trust the npm publisher and are comfortable with a global CLI that can update from npm, store Kugou login state locally, read favorites/recent listening/statistics, change recommendations or playlists, and control the local Kugou client. Prefer QR login over pasting a base64 secret, and avoid providing secrets in chat or command history unless you understand that they grant account access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned External npm Package Is Installed Globally and Can Be Updated to a Mutable Latest Release

Content
View full analysis
Remediation
View remediation
``` 2. Publish the complete CLI source code alongside the Skill so that executable behavior can be included in security review. 3. Provide and verify an integrity digest, signed provenance statement, or trusted npm provenance record for every approved release. 4. Audit and lock all transitive dependencies. Include a lockfile in the source distribution and use reproducible release procedures. 5. Avoid global installation where practical. Prefer a project-local, isolated installation with a restricted execution environment and least-privilege filesystem access. 6. Disable npm lifecycle scripts during installation when they are not required: ```bash npm install --ignore-scripts @kg-ai/kugou-skill@ ``` If lifecycle scripts are required, document and audit each script before installation. 7. Require explicit user confirmation immediately before both initial installation and every update. Display the exact version, registry, and command that will be executed. 8. Do not automatically trust the `latest` distribution tag. Retrieve available release metadata, validate it against an approved version list and integrity record, and only then perform the update. 9. Document recovery procedures for removing a compromised global installation, rotating locally stored authentication secrets, and reinstalling a known-good release. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are broad enough to activate on generic music-related requests, which can cause the agent to invoke this skill in situations where the user did not clearly intend to use Kugou. Because the skill includes login handling, local client control, and account-linked operations, accidental activation can lead to unnecessary credential prompts, unintended account actions, or privacy-relevant queries against a user's music profile.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly encourages users to provide a base64 secret for login import but does not present strong safeguards, minimization guidance, or warnings that this secret is a sensitive authentication credential. If mishandled, echoed, logged, or requested in the wrong context, the secret could enable account takeover or unauthorized access to the user's music account and associated personal data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Triggering solely on mention of words like '酷狗', '猜你喜欢', or '相似歌曲' lacks contextual validation and increases the chance of false activation from casual discussion, comparison, or unrelated references. In this skill, false activation is more dangerous than a simple UX issue because the workflow can proceed into authentication, profile access, recommendation feedback submission, or local playback control.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly tells the agent to ask the user whether they already have a base64 secret and to use that secret for authentication. Soliciting reusable credentials through conversational channels is risky because the value may be captured by the agent platform, conversation transcripts, prompt logs, shell history, or other observers, and the secret appears sufficient to assume the user's authenticated session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs users to paste a reusable base64 authentication secret directly into the CLI and states that it will be persisted locally, but it does not clearly warn that this secret is effectively credential material. In an agent-mediated workflow, asking for such a secret increases the chance of credential disclosure in chat logs, shell history, telemetry, or screenshots, and local persistence broadens the exposure window if the host is shared or compromised.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section operationalizes credential pasting by giving a concrete command that embeds the secret in plain command-line arguments. That creates multiple exposure points, including terminal scrollback, process listings on some systems, shell history, remote session logs, and agent/tool telemetry, making account compromise more likely if the secret is intercepted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill guide is written in Chinese and repeatedly includes AI-facing instructions such as 'AI 必读' without any indication that the agent may respond in another language if the user prefers. Under the policy rule, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is documented and justified, which it is not here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill exposes and manipulates personalized listening-history and preference data such as favorites, recent playback, listening statistics, and recommendation preferences, but the documentation does not clearly warn that these are privacy-sensitive actions. In an agent setting, this increases the risk of users or orchestrators invoking account-linked data retrieval or preference changes without informed consent, leading to unintended disclosure or modification of personal behavioral data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and all presentation requirements are written as mandatory Chinese output conventions, and the file repeatedly uses prescriptive language such as '必须遵循以下规范'. There is no indication that users may choose another language or that the Chinese-only requirement is limited to a justified region-specific context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file documents a built-in self-update mechanism that checks npm on every CLI invocation and can directly trigger a global package upgrade. For a music-assistant skill, this introduces package-management behavior outside the expected functional scope, creating an unnecessary supply-chain and execution surface if an agent or user follows the documented update path without strong trust controls.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This section explicitly instructs agents/scripts to run kugou-cli update --force and even npm install -g @kg-ai/kugou-skill@latest, which can modify the host environment globally. In the context of a music skill, documenting agent-driven global installation/update commands is risky because it normalizes privileged package execution unrelated to serving music recommendations or playback control.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document consistently uses Chinese for command guidance and even prescribes exact Chinese prompts such as asking the user whether they already have a base64 secret. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is justified or optionality is offered.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all operational guidance exclusively in Chinese, and there is no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy check, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file presents all instructions, prompts, and examples exclusively in Chinese, which can amount to a language/locale policy violation when no user opt-in or documented locale constraint is provided. There is no indication that the skill is limited to a Chinese-speaking or region-specific audience by design.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

L003 的总述写明“所有 music 命令都需要先登录”,但后文只有部分高风险/个性化命令被单独标注为需要登录,且如搜索、榜单、歌单搜索/推荐等命令并未标注登录要求。这会让技能宣称的使用前提与实际能力范围不一致,属于文档层面的描述—行为不匹配。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.