Back to skill

Security audit

Apple Music Play

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it ships an under-disclosed playlist script with an AppleScript injection risk that could let crafted input run unintended local automation.

Review this skill before installing. The playback automation is expected for its purpose, but it needs Accessibility and Automation permissions and can send music searches to Apple. Avoid using the bundled playlist_create.py script with untrusted playlist names until its AppleScript handling is fixed or removed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/playlist_create.py:31
Finding

Arbitrary AppleScript Injection Through Unsanitized Playlist Name

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script programmatically sends keypresses to the Music app via osascript/System Events after opening a music:// URL, causing UI-driven actions without explicit user consent at execution time. This can trigger unintended playback or interact with the focused Music UI state in ways the user did not anticipate, which is especially risky in an agent skill context where actions may run non-interactively.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/catalog_play.py (reported line 15)May include surrounding context.

python
def run(cmd):
    return subprocess.run(cmd, text=True, capture_output=True)


def current_track():

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/catalog_play_experiment.py (reported line 15)May include surrounding context.

python
def run(cmd):
    return subprocess.run(cmd, text=True, capture_output=True)


def current_track():

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/clawtunes_play.py (reported line 10)May include surrounding context.

python
def run(cmd):
    return subprocess.run(cmd, text=True, capture_output=True)


def current_track():

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/playlist_create.py (reported line 14)May include surrounding context.

python
def run(cmd):
    return subprocess.run(cmd, text=True, capture_output=True)


def current_track():

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sends user-supplied search terms to Apple's iTunes search API without any disclosure, confirmation, or privacy notice. This can expose potentially sensitive user interests or internal project names to a third party, which is risky in an agent skill context where users may not expect outbound network access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script automates Music.app and System Events to create playlists, open external links, and simulate keystrokes that modify the user's library without an explicit confirmation step. In an agent setting, UI scripting and application automation are sensitive because they can trigger unintended actions on the host and train users to accept opaque automation touching local apps.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The user's query is transmitted to Apple's iTunes Search API without any notice, which creates an information disclosure/privacy issue. While the destination is expected and the data is limited to the search term, the lack of disclosure is still relevant for a skill that may process user-provided content automatically.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.