Back to skill

Security audit

CellCog音乐生成免费版

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a CellCog music-generation guide, but it advertises unrelated video, media conversion, automation, and code-generation uses while declaring exec/write authority.

Install only if you intend to use it for CellCog text-to-music or lyrics-to-music generation. Keep the CellCog API key private, review commands before execution, and avoid relying on this skill for video processing, media conversion, dubbing, automation, API design, or code generation unless the publisher narrows and documents those capabilities.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The skill metadata claims the tool should be used for unrelated tasks such as video processing, media conversion, dubbing, API design, and code generation, while the documented operations only cover music generation. This can cause an agent to invoke the skill in inappropriate contexts, leading to unsafe tool routing, misleading outputs, or unintended execution with read/exec/write privileges.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The description overclaims capabilities beyond music generation, which can mislead orchestration systems or users into selecting this skill for unsupported tasks. In a skill that exposes exec/write tools, incorrect activation increases the chance of unintended command execution, data handling, or policy bypass through capability confusion.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The capability coverage section asserts support for many keywords and scenarios that are not represented in the actual operations, effectively broadening the activation surface of the skill. This makes the skill more likely to be selected for unrelated tasks and can amplify misuse because the skill is classified as MD+EXEC and includes read/exec/write tools.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keywords include broad and unrelated terms such as API design, code generation, automation, conversion, design, and video, which can cause the skill to activate outside its intended domain. Because the skill has access to exec/write tooling, overbroad activation materially raises the risk of inappropriate tool use and cross-domain prompt routing failures.

Vague Triggers

High
Confidence
95% confidence
Finding
The activation guidance mixes incompatible use cases without clear boundaries, making it ambiguous when the skill should be used. Ambiguous routing is especially risky here because the skill presents itself as executable and networked, so a user asking for unrelated media or development tasks could trigger unnecessary external calls or command execution.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.