Back to skill

Security audit

音乐生成工具专业版

Security checks for vulnerabilities and agentic risk

Overview

The skill is a music-generation guide, but its broad activation text and generic input schema do not adequately scope its read, write, command-execution, external API, and CI/CD behaviors.

Install only if you intend to use it for music-production automation and are comfortable reviewing every command, generated workflow, dependency install, output path, and API credential scope first. Use a project-local workspace, a nonprivileged virtual environment, pinned dependencies, least-privilege API keys, and avoid running its scripts or copied CI workflows as administrator/root.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:353
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 353-354
Vulnerability Type: Unpinned and integrity-unverified package installation
Risk Level: Medium

text
| Audio processing library | Library | Recommended | pip install pydub |
| Audio analysis library | Library | Recommended | pip install librosa |

Technical Analysis

The installation commands do not specify reviewed package versions, dependency hashes, a lock file, or a trusted package index. Package resolution therefore depends on mutable releases and the invoking environment's package-index configuration.

If an upstream package, transitive dependency, or configured package index is compromised, following these instructions could install attacker-controlled code. The project does not itself contain a malicious dependency, so this is a supply-chain exposure rather than evidence of intentional malicious behavior.

Attack Path

  1. A user follows the dependency installation instructions.
  2. pip resolves the latest compatible packages and their transitive dependencies from the configured index.
  3. An upstream release, dependency, or package-index response has been compromised.
  4. The malicious package is installed into the selected Python environment.
  5. Attacker-controlled code executes during package installation, import, or subsequent audio-processing operations.

Impact Assessment

Malicious dependency code would execute with the privileges of the account running pip or the consuming Python process. Potential impact includes access to readable project files, environment variables, API credentials, generated assets, and writable files. If installation is performed under an elevated account, the impact could extend to system-wide modification.

Remediation
View remediation

Remediation Suggestions

  • Pin all direct and transitive dependencies to reviewed versions.
  • Maintain a committed lock file generated through a controlled dependency-review process.
  • Require package hashes, such as with pip install --require-hashes.
  • Explicitly configure an approved HTTPS package index and disable unapproved extra indexes.
  • Install dependencies inside an isolated, nonprivileged virtual environment.
  • Scan dependencies for known vulnerabilities and review updates before changing pins.
  • Avoid running package installation as an administrator or root user.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:421
Finding

GitHub Actions Referenced Through Mutable Version Tags

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 421-437
Vulnerability Type: Mutable CI/CD supply-chain dependencies
Risk Level: Medium

yaml
- uses: actions/checkout@v3
- name: Setup Python
  uses: actions/setup-python@v4
  with:
    python-version: "3.10"
- name: Batch Generate Music
  run: |
      --config music-tasks/config.yml \
      --parallel 5 \
      --auto-select-platform \
      --quality-check
- name: License Audit
  run: |
      --library ./music-library/ \
      --report ./audit/
- name: Upload Music
  uses: actions/upload-artifact@v3
  with:
    name: music-assets
    path: ./music-library/

Technical Analysis

The CI/CD example references GitHub Actions by major-version tags rather than immutable full commit SHAs. Tags are mutable references, so the implementation executed by a copied workflow can differ from the implementation originally reviewed. The example also uses older major versions, increasing maintenance and lifecycle concerns.

Compromise of an upstream action repository or unauthorized movement of a referenced tag could cause attacker-controlled code to execute in the workflow runner. No such upstream compromise is established by the audited file; the vulnerability is the absence of immutable dependency pinning.

Attack Path

  1. A team copies the documented workflow into a repository.
  2. GitHub Actions resolves actions/checkout@v3, actions/setup-python@v4, or actions/upload-artifact@v3 when the workflow runs.
  3. An upstream account or repository is compromised, or a mutable tag is otherwise redirected to an unauthorized commit.
  4. The runner downloads and executes the changed action implementation.
  5. The hostile action accesses resources available to the workflow, such as checked-out source, generated music assets, environment variables, or workflow credentials.

Impact Assessment

Exploitation could obtain the permi ...[truncated 409 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin every third-party action to a reviewed full commit SHA rather than a branch or version tag.
  • Record the corresponding release version in a comment for maintainability.
  • Upgrade obsolete action versions after compatibility and security review.
  • Configure explicit job-level permissions and grant only the minimum required scopes.
  • Do not expose secrets to jobs or steps that do not require them.
  • Use dependency-update tooling to propose reviewed SHA updates.
  • Apply organization-level allowlists for approved GitHub Actions.
  • Treat generated artifacts as untrusted until integrity and content checks complete.

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:491
Finding

Blanket Recommendation to Retry Commands with Administrator Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 491
Vulnerability Type: Unsafe privilege-elevation guidance
Risk Level: Low

text
| Insufficient permissions | The current user lacks read/write permissions | Check file permissions and run as administrator |

Technical Analysis

The troubleshooting guidance recommends administrator execution as a generic response to insufficient read/write permissions. It does not require identification of the exact protected resource, correction of ownership, use of a user-writable directory, or narrowly scoped elevation.

This is especially risky because the skill declares command-execution capability and refers to several Python scripts that are not included in the audited project. Those absent scripts cannot be verified. Elevating an unknown, substituted, or dependency-compromised command would unnecessarily expand its authority.

Attack Path

  1. A referenced command fails because its input or output path is not writable.
  2. The user follows the troubleshooting guidance and reruns the command as an administrator or root-equivalent account.
  3. A local script has been substituted, or one of its dependencies has been compromised.
  4. The untrusted code executes with elevated privileges.
  5. It modifies or reads resources that would have been inaccessible to the original user.

Impact Assessment

The immediate impact is unnecessary execution with administrator-level authority. If the elevated command were malicious, potential scope could include system-wide file modification, access to protected local data, installation of software, and alteration of security-sensitive configuration. The audited file does not itself perform elevation and contains no embedded malicious script, so exploitation requires a user to follow the recommendation and execute compromised or substituted code.

Remediation
View remediation

Remediation Suggestions

  • Remove generic advice to rerun commands as an administrator.
  • Direct users to inspect the exact path, ownership, and required access operation.
  • Use project-local or user-writable input, output, cache, and virtual-environment directories.
  • Grant only the minimum permission required for the specific resource.
  • Require review of the exact executable, script path, and arguments before any elevation.
  • Never elevate scripts or dependencies that are absent from the reviewed project.
  • If elevation is unavoidable, use a narrowly scoped mechanism and document the precise command and required privilege.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation guidance is overly broad, recommending use for general efficiency, automation, workflow optimization, and even unrelated media-processing tasks. Because the skill has read/exec/write capabilities, vague routing criteria can cause it to activate for ordinary productivity requests and perform unnecessary system or file operations beyond the user’s actual intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description states '支持中文交互,无需复杂配置即开即用,' which presents Chinese interaction as the expected mode without indicating that other languages are available by user choice. This can violate language/locale policy when the skill does not explicitly offer opt-in or alternatives.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill includes markdown examples that initialize libraries, import assets, generate indexes, and run audit scripts using exec and write-like behavior, but it does not provide a prominent upfront warning that these actions can modify local files or invoke external services. In a skill with execution capability, burying side-effect information increases the chance that users or calling agents trigger system changes without informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill’s declared request/output schema describes a generic text-processing interface while the rest of the document presents a music-generation, file-writing, and command-execution tool. This mismatch can cause the agent to invoke the skill under unrelated prompts and then perform side-effecting actions (exec/write) the user did not clearly intend, increasing the risk of confused-deputy behavior and unsafe automation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.