Back to skill

Security audit

ai-music-and-sound

Security checks across malware telemetry and agentic risk

Overview

This text-only skill coherently guides users toward licensed music and sound design for social videos without hidden execution or overbroad authority.

Before installing, be aware that the skill may ask the agent to look at your brand profile and video assets to match audio to the edit. It also points users toward paid third-party music or stock-audio services and reminds them to keep license records; legal and platform terms should be rechecked for important commercial work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Unrestricted Tool Access

Medium
Category
Excessive Agency
Content
- **Pairs with:** `ai-voiceover` (voice + music together), `reels-script`/`tiktok-script` (the edit it
  scores), `captions-and-clipping` (captions over the same video), `ai-video` (when the video tool's native
  audio is enough).
- **Tools:** ElevenLabs Music/SFX, Suno, Udio, Stable Audio + stock libraries (Epidemic/Artlist/Soundstripe)
  — connection/license/litigation facts + the WoopSocial flow: `tools/integrations/ai-music-and-sound.md`
  (and `tools/integrations/elevenlabs.md` for the ElevenLabs side).
- **Publishes via:** the **creator bakes audio in** → `scheduling-and-queue → WoopSocial` (the finished
Confidence
26% confidence
Finding
Tools:*

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.