Back to skill

Security audit

ACE音乐生成-免费版

Security checks across malware telemetry and agentic risk

Overview

This music-generation skill is not clearly malicious, but it asks for command execution while its activation text and capabilities are broader than its stated music purpose.

Review before installing. Use this only for ACE music generation, verify any scripts or commands before running them, and provide the API key through a controlled environment variable. Avoid letting it auto-handle unrelated video, media conversion, generic agent, or file-processing tasks.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The skill is advertised as a narrow music-generation tool, but these sections introduce generic CRUD-style operations and configurable execution patterns unrelated to that purpose. In an agent ecosystem, this kind of scope drift can cause the skill to be selected for tasks it was never meant to handle, increasing the chance of unsafe tool use or unintended command execution under misleading documentation.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The trigger conditions broaden the skill from music generation into video processing, audio editing, media conversion, and dubbing, which materially expands when an agent may invoke it. Because the skill has exec capability, overbroad activation criteria can route unrelated user requests into a command-executing skill, creating unnecessary exposure to misuse or unsafe command construction.

Vague Triggers

High
Confidence
94% confidence
Finding
An overly broad trigger description is dangerous because it can cause automatic skill selection for generic requests far outside the intended function. In this case the risk is amplified by the presence of exec and write capabilities, since accidental invocation may lead an agent to run commands or create files in contexts where a specialized music skill should never have been used.

Vague Triggers

High
Confidence
95% confidence
Finding
The description includes broad guidance like AI model calling, intelligent dialogue, agent orchestration, and LLM applications, which makes this skill appear applicable to many generic agent tasks. In a tool-routing environment, this can hijack requests away from safer or more appropriate skills and funnel them into a skill with execution capability and mismatched documentation.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.