Back to skill

Security audit

音乐

Security checks across malware telemetry and agentic risk

Overview

This skill is a music-generation guide, but it asks for broad command execution and file write authority without clear limits or an enforceable command whitelist.

Review before installing. This does not show malicious behavior or hidden exfiltration, but it grants a user's agent broad shell and file mutation capability for a loosely specified music workflow. Install only if you trust the publisher and can constrain execution to known media tools, explicit user-selected files, and non-sensitive working directories.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill advertises a music-generation purpose but requests broad `exec` capability alongside read/write access, with no concrete justification tying shell execution to narrowly scoped audio operations. In an agent environment, unnecessary command execution materially expands the attack surface and can be abused to run arbitrary local commands, access files, or chain into data exfiltration.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The document claims only whitelisted commands should be executed, yet the skill exposes unrestricted `exec` capability and does not define any actual whitelist or enforcement mechanism. This mismatch is dangerous because users and agents may assume command safety controls exist when in practice arbitrary execution remains available.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.