Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

MusicGenerator

v1.0.0

AI music generation assistant powered by MakebestMusic. Use when user wants to create AI-generated music, songs, or audio tracks. Perfect for content creator...

0· 206·0 current·0 all-time
byMakeBestMusic@sthk-mbm·duplicate of @sthk-mbm/texttomusic

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for sthk-mbm/musicgenerator.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "MusicGenerator" (sthk-mbm/musicgenerator) from ClawHub.
Skill page: https://clawhub.ai/sthk-mbm/musicgenerator
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Required env vars: apiKey
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install musicgenerator

ClawHub CLI

Package manager switcher

npx clawhub@latest install musicgenerator
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name, description, SKILL.md, and the two scripts are consistent with an AI music generation assistant that talks to MakebestMusic. The only required secret is an apiKey which is appropriate for this purpose.
!
Instruction Scope
SKILL.md instructs running the included node scripts and shows expected outputs, which is consistent. However the runtime code reads an undocumented environment variable MBM_API_BASE (defaulting to the official API). That undocumented override lets callers redirect network calls to an arbitrary endpoint without the user being informed in SKILL.md. Also the SKILL.md uses the skill folder name text-to-music while registry metadata uses slug musicgenerator — a minor mismatch in paths/naming that could cause confusion.
Install Mechanism
No install spec or external downloads — the skill is instruction-only with included JS scripts. No remote archive or package installs were found.
!
Credentials
Only one required env var (apiKey) is declared and used, which matches the skill purpose. However the code also reads MBM_API_BASE (not declared in SKILL.md/metadata) which can change the target endpoint. The primary credential name is generic (apiKey) but SKILL.md explains it should be the MakebestMusic/Claw key.
Persistence & Privilege
always is false and the skill does not request system-wide changes or persistent privileges. It only runs short-lived node processes; no indication it modifies other skills or agent configs.
What to consider before installing
This skill largely does what it claims: it sends your apiKey to MakebestMusic endpoints to start and check music generation. Before installing, consider the following: - The code accepts an undocumented MBM_API_BASE env var which, if set, will redirect API calls to a different domain. Ask the publisher to declare or remove this override. Do not set MBM_API_BASE unless you control and trust the target host. - Use a dedicated/limited API key for this skill (not a high-privilege or multi-service secret). Rotate the key if you stop using the skill. - Verify the API endpoint is the official https://api.makebestmusic.com (the script defaults to it). Confirm the domain and review MakebestMusic privacy/terms for generated lyrics/audio handling. - The SKILL.md references a folder name text-to-music while registry slug is musicgenerator — check that paths work in your OpenClaw install before relying on the example commands. - If you need stronger assurance, request the author to: (1) document MBM_API_BASE in SKILL.md or remove the override, (2) rename apiKey to something vendor-scoped in metadata, and (3) confirm there are no other telemetry or logging endpoints. I have medium confidence because the code is small and mostly consistent, but the undocumented endpoint override is a real risk vector and justifies extra caution.
scripts/generate.js:3
Environment variable access combined with network send.
scripts/query.js:3
Environment variable access combined with network send.
Patterns worth reviewing
These patterns may indicate risky behavior. Check the VirusTotal and OpenClaw results above for context-aware analysis before installing.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🎵 Clawdis
EnvapiKey
Primary envapiKey
latestvk978d6jrqhk64cfg061db73rv1833jqn
206downloads
0stars
1versions
Updated 21h ago
v1.0.0
MIT-0

🎵 AI Music Studio

✨ Describe your vision, let AI compose the melody ✨


🚀 Get Your API Key

  1. Visit 👉 MBM官网 and sign up 📝
  2. Go to My Account → Claw key 🔑
  3. Click Create Key and copy it ✂️
  4. ⚠️ Important: Save your key immediately — it won't be shown again!

⚙️ Configure Your Key

  1. Open OpenClaw app 📱
  2. Click Skills in the left menu 📋
  3. Find text-to-music 🎶
  4. Click Configure or Environment Variables
  5. Enter your Claw key (xxx...) in the apiKey field 🔐
  6. Save — you're ready to go! 🎉
  7. Restart openclaw

💫 How It Works

Just tell me what kind of song you want! For example:

  • "Create a happy pop song about summer"
  • "Generate an upbeat K-pop dance track"
  • "Make a relaxing piano piece for studying"

Instrumental or Vocals?

  • If you want vocals (song with singing): just describe your song
  • If you want pure music (no singing): include words like "instrumental", "pure music", or "no vocals" in your request

What to include in your description:

  • 🎼 Genre: Pop, Electronic, Classical, Rock, Jazz, R&B, Hip-hop, K-pop, Chinese-style
  • 😊 Mood: Happy, Sad, Romantic, Energetic, Calm, Exciting
  • 💖 Theme: Love, Dreams, Nature, Night, Adventure
  • 🎸 Instruments: Piano, Guitar, Drums, Synth, Strings

I'll default to vocals if you don't specify!


💬 Example Requests

With Vocals (Default)

  • "Create a happy pop song about summer with synth and guitar"
  • "Generate an upbeat K-pop dance track about love"
  • "Write a romantic R&B song about heartbreak"
  • "Make an energetic electronic song for a workout"

Instrumental

  • "Create an instrumental piano piece for studying"
  • "Generate a relaxing ambient track, no vocals"
  • "Make a pure music classical piano piece"

Check Status

  • "How's my song going?"
  • "Is my song ready?"

🎵 Generating a Song

When user requests a song:

  1. If user provides description: Use their description, default to vocals (false) unless they explicitly say "instrumental" or "pure music"
  2. If user says "create a song" or "generate music" without description: Ask them what kind of song they want

Then run:

node ~/.openclaw/workspace/skills/text-to-music/scripts/generate.js "<prompt>" <instrumental>

Parameters:

  • <prompt>: Song description
  • <instrumental>: "true" for instrumental/pure music, "false" for vocals

Returns:

{
 "success": true,
 "music_ids": ["abc123", "def456"],
 "status": "pending",
 "message": "Music generation started!"
}

🔍 Query Task Status

Check generation status:

node ~/.openclaw/workspace/skills/text-to-music/scripts/query.js "<music_id_1> <music_id_2> ..."

Returns (completed):

[
 {
 "music_id": "abc123",
 "status": "completed",
 "url": "https://makebestmusic.com/app/shared-music/abc123"
 }
]

Returns (processing):

[
 {
 "music_id": "abc123",
 "status": "pending"
 }
]

Status handling:

  • completed: Present with celebration! Show title, duration (if available), and clickable link
  • pending: Tell user it's still processing, suggest they ask again later
  • failed: Explain failure, suggest retrying with different description

⏱️ Generation Time

  • ⏱️ Typical time: 2-3 minutes
  • 💡 Ask "How's my song going?" to check the status

❓ Troubleshooting

Q: "API Key invalid" error?

Make sure the key is copied completely (includes "sk-" prefix). No extra spaces. Try generating a new key if issues persist.

Q: How long does it take?

Usually 2-3 minutes. Ask me "How's my song going?" to check!

Q: What if generation fails?

Try a simpler description. Avoid special characters. Try again with different keywords.

Comments

Loading comments...