Back to skill

Security audit

音乐生成工具专业版

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a music-generation workflow, but its activation language is too broad for a skill that can run commands and write files.

Install only if you want an agent to help with music generation, music library management, and related audit/report files. Before use, constrain it to music-specific tasks and review any command, file write, API-key, database, or CI/CD action before allowing execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
84% confidence
Finding
The skill uses extremely broad activation language such as improving efficiency, automation, batch processing, and workflow optimization, which could cause an agent to invoke it for many unrelated tasks. In a skill that has read/exec/write capabilities, overbroad matching increases the chance of unintended command execution or file modification in contexts the user did not specifically authorize.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This section documents command execution and file-writing workflows, including scripts that generate, import, audit, and write artifacts, but it does not provide a strong upfront warning that the skill can change the filesystem or invoke external commands. In an agent environment with exec/write tools, insufficient disclosure can lead users or orchestration layers to trigger system-changing actions without informed consent, increasing the risk of accidental destructive changes or abuse through loosely scoped tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.