Back to skill

Security audit

ACE Music AI音乐LITE

Security checks across malware telemetry and agentic risk

Overview

This is a text-to-music helper that uses an ACE Music API key and local CLI-style commands, with some confusing overbroad wording but no hidden persistence, destructive behavior, or exfiltration instructions found.

Install only if you want an agent to help generate music through ACE Music. Expect it to use an ACE_MUSIC_API_KEY and write MP3 files locally. Because the skill text is overbroad and somewhat inconsistent, avoid relying on it for video editing, media conversion, dubbing, cover songs, or editing existing audio unless the publisher narrows and clarifies those instructions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
76% confidence
Finding
The skill description uses broad invocation language covering video processing, audio editing, dubbing, and media conversion even though the skill appears focused on text-to-music generation. Overbroad triggers can cause an agent to invoke this skill in unrelated contexts, increasing the chance of unintended command execution, misuse of API-backed tooling, or handling of user content outside the intended security boundary.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.