Back to skill

Security audit

Text to Song

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its music-generation purpose, but it handles an API key and user prompts with under-disclosed third-party transmission and an undocumented endpoint override that could redirect them.

Review this skill before installing. Use a dedicated MakebestMusic key with limited exposure, avoid putting private or confidential text in prompts, and only run it in an environment where MBM_API_BASE cannot be set to an untrusted endpoint. The behavior is not clearly malicious, but the credential-handling and disclosure gaps are significant enough to warrant caution.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate.js:3
Finding

API credential and user prompt can be redirected to an attacker-controlled endpoint

Content
View full analysis
[instrumental(true/false)]"); process.exit(1); } async function generate() { try { const res = await fetch(`${API_BASE}/api/skill/generate_music`, { method: "POST", headers: { "Content-Type": "application/json", Authorization: `Bearer ${API_KEY}`, }, body: JSON.stringify({ model: "Fi", custom: true, instrumental: instrumental, prompt: prompt, title: "", style: "", advance: { vocal_gender: "", ai_lyrics: true } }), }); ``` ### Technical Analysis The script takes the API destination from the `MBM_API_BASE` environment variable and unconditionally sends the configured `apiKey` to that destination in an `Authorization` header. It does not validate the URL scheme or hostname before transmitting the credential. The endpoint override is not documented as necessary for the Skill's declared production functionality. Normal operation only requires access to `https://api.makebestmusic.com`. Consequently, allowing an arbitrary override expands the trust boundary beyond the minimum privileges required. The request body also contains the user's music prompt. If the environment ...[truncated 1395 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/query.js:3
Finding

API credential and music identifiers can be redirected during status queries

Content
View full analysis
...'"); process.exit(1); } // Split by space or comma const ids = musicIds.split(/[\s,]+/).filter(id => id.trim()); const musicIdsParam = ids.map(id => `music_ids=${encodeURIComponent(id)}`).join('&'); async function query() { try { const res = await fetch(`${API_BASE}/api/skill/music_status?${musicIdsParam}`, { headers: { Authorization: `Bearer ${API_KEY}`, }, }); const data = await res.json(); ``` ### Technical Analysis The status-query script uses the environment-controlled `MBM_API_BASE` value as the request origin and sends the API key to that origin as a Bearer credential. There is no HTTPS requirement, hostname allowlist, or validation that the final destination is the documented MakeBestMusic service. The queried music identifiers are also included in the URL query string. Redirecting the endpoint therefore exposes both the API credential and task metadata. Because query strings may be retained in server access logs, reverse-proxy logs, and monitoring systems, music identifiers can additionally be recorded by the substituted endpoint's infrastructure. The default request to the legitimate MakeBestMusic endpoint is consistent with the declared status-query functionality. The arbitrary endpoint override ...[truncated 1222 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes local Node.js scripts and requires both environment access and outbound network access, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege enforcement and makes it harder for the platform or reviewer to constrain what the skill is allowed to do, increasing the blast radius if the scripts are modified or abused.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: text-to-music
description: AI music generation assistant powered by MakebestMusic. Use when user wants to create AI-generated music, songs, or audio tracks. Perfect for content creators, musicians, and anyone wanting custom AI music. Triggers on requests like "create a song", "generate music", "makebestmusic", "AI music", "write a melody", etc.
version: 1.2.0
metadata:
  openclaw:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad and generic, such as 'create a song', 'generate music', and 'AI music', which can cause the skill to activate in situations where the user did not clearly intend to use this external service. Unintended activation can lead to unexpected data sharing, surprise API usage, or accidental generation requests billed against the user's key.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explains how to generate songs but does not clearly warn users that their prompts will be transmitted to MakebestMusic, an external third-party service. Users may unknowingly send personal, sensitive, or proprietary content off-platform without informed consent, creating privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sends the user-provided prompt to a remote API and includes an authorization bearer token, which is a privacy- and security-relevant network operation. While there is error handling, there is no confirmation prompt, warning comment/docstring, or user-facing notice in this file explaining that prompt content will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The setup instructions include the Chinese phrase "MBM官网" inside otherwise English guidance, which introduces a language-specific element without offering user choice or explaining the locale requirement. This can conflict with language/locale policy expectations when a skill otherwise appears to target general users.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/generate.js:3

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/query.js:3