Back to skill

Security audit

Ace Music Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a music-generation helper, but its instructions are inconsistent and under-specified enough that users should review it before installing.

Install only if you are comfortable reviewing and constraining its use to music generation. Confirm what script or command will actually run, avoid using it for general video/audio/media conversion work, and do not submit sensitive lyrics, prompts, or credentials unless you accept processing by the external ACE Music API.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as an AI music generator, but its trigger condition expands usage to video processing, audio editing, media conversion, and voice generation. This scope inflation can cause an agent to invoke the skill for unrelated tasks and potentially execute commands or handle data outside the user’s expected consent and the skill’s documented safety boundary.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The document says broad media-processing scenarios are out of scope, but later recommends using the skill for video processing, audio editing, and media conversion. These contradictory instructions weaken routing safeguards and can mislead an agent into selecting the skill for unsupported operations, increasing the chance of unsafe or unintended tool execution.

Intent-Code Divergence

Low
Confidence
84% confidence
Finding
The 'technical implementation' section claims generic create/query/update/delete-style operations and import/export/reset behaviors that do not match the rest of the skill, which mainly describes a single music-generation shell script. This ambiguity can cause an agent to infer unsupported control surfaces or stateful operations and act beyond the intended function.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger condition is overly broad and extends beyond music generation into adjacent media tasks. In an agent environment, overly permissive activation criteria raise the risk of incorrect skill selection, accidental command execution, and user data being sent to an external service for tasks the user did not intend to delegate to this skill.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill depends on an external API but does not clearly warn that prompts, lyrics, and related user content will be transmitted off-platform. This creates a data-handling and privacy risk because users may provide sensitive creative material or personal information without informed consent about third-party processing.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.