Back to skill

Security audit

Home Music

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed home-audio control script; it has some rough scoping and documentation issues but no evidence of hidden, deceptive, destructive, or data-stealing behavior.

Install only if you intend this skill to control Spotify and Airfoil speakers on macOS. Consider narrowing the triggers, avoiding the optional sudo symlink if you do not need a global command, and fixing the reading-scene speaker names before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The core behavior matches the declared purpose: the script controls Spotify playback and Airfoil speaker routing for household music scenes such as morning, party, chill, and stop. However, there are additional user-facing capabilities not represented in the description/triggers: a 'reading' music scene and a 'status' command that reports Spotify and speaker state. Those are materially exposed functions beyond the declared presets. Also, the reading scene operates on 'Living Room' and 'Bedroom' speakers, which do not match the configured ALL_SPEAKERS list shown elsewhere, indicating resource/behavior inconsistency. This is not a severe purpose mismatch, but it is still a description-behavior mismatch due to undeclared capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to match common conversational requests about music, which can cause unintended activation of this skill. In a home-automation context, that means the agent could unexpectedly start playback across speakers or stop music based on ambiguous user phrasing.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
94% confidence
Finding

The trigger 'stop music' is close to a built-in stop-style command and can shadow or conflict with core assistant behavior. That can cause the wrong handler to run, leading to unintended speaker disconnects or pausing Spotify when the user meant to stop speech, playback, or another action.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

chmod +x ~/clawd/skills/home-music/home-music.sh

Symlink for global access

sudo ln -sf ~/clawd/skills/home-music/home-music.sh /usr/local/bin/home-music

text

Now `home-music` works from anywhere in your terminal! 🎉

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example phrases encourage ambiguous natural-language activation beyond the exact documented command names. That broadens the effective trigger surface and increases the chance that normal conversation or loosely phrased requests invoke whole-house audio actions unintentionally.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The comments for the reading scene say it will use 'Living Room + Bedroom at 20% volume', but the code actually connects and sets volume for speakers named 'Living Room' and 'Bedroom'. This directly conflicts with the configured speaker inventory, which lists 'Living Room TV' and does not include 'Bedroom', so the documented intent does not match the implemented behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script's configured speaker inventory lists "Computer", "Andy's M5 Macbook", "Sonos Move", and "Living Room TV", but the reading scene attempts to connect and control "Living Room" and "Bedroom" instead. Because this code issues device-control actions without any confirmation and without warning that it may target mismatched or unintended speakers, users are not clearly informed about the attempted system changes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The help output claims the reading scene runs on 'Living Room + Bedroom', but the declared available speakers list contains 'Living Room TV' and no 'Bedroom'. This is an intent/documentation mismatch that can mislead users about what the skill actually controls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.