Back to skill

Security audit

音乐

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only music skill that requests broad read, write, and command execution authority without a supporting implementation or clear limits.

Review this carefully before installing. It does not contain malicious code, but it asks for powerful local capabilities without showing how they are safely used. Only install it in a sandboxed agent environment, avoid granting unrestricted command execution or broad filesystem access, and do not provide sensitive API keys unless the publisher supplies a concrete, scoped integration.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:17
Finding

Excessive Tool Permissions Without a Supporting Implementation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17-20
Vulnerability Type: Excessive command-execution and filesystem permissions
Risk Level: Medium

yaml
tools:
- read
- exec
- write

Technical Analysis

The skill requests command execution and filesystem read/write capabilities even though the package contains only SKILL.md and provides no executable music-generation implementation, processing script, constrained file workflow, or documented command set requiring these privileges.

This violates the principle of least privilege. In particular, the unrestricted exec capability creates a command-execution channel, while read and write expose local files to access and modification. The document does recommend command allowlisting and avoiding interpolation of user input, but it does not implement or enforce those controls.

Exploitation would depend on the host agent granting the declared tools and allowing skill instructions or attacker-controlled task content to determine tool arguments. Under those conditions, the permissions could be used for operations unrelated to music generation.

Attack Path

  1. A host agent loads the skill and grants its declared read, write, and exec tools.
  2. An attacker supplies crafted task content, a prompt, or a referenced file that induces the agent to perform operations outside the skill's stated purpose.
  3. The agent invokes read to inspect accessible local data, write to alter accessible files, or exec to run an unauthorized local command.
  4. The operation executes with the privileges and filesystem access of the agent process, crossing the legitimate privilege boundary of a documentation-only music-generation skill.

No fixed malicious command, exfiltration endpoint, persistence mechanism, or embedded payload was found in the audited file; therefore, the exploitability and resulting scope are conditional on the host's tool authoriza ...[truncated 715 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove exec, read, and write from the tool declaration unless each capability is required by an implemented workflow.
  2. Prefer a dedicated, narrowly scoped music-generation API tool rather than general command execution.
  3. If filesystem access is necessary, restrict it to explicit input and output directories using canonicalized paths and deny traversal outside those directories.
  4. If command execution is indispensable, enforce a fixed executable allowlist and structured arguments. Never pass user-controlled content through a shell or construct command strings by concatenation.
  5. Run the skill in a sandbox with minimal operating-system privileges, no access to unrelated secrets, a read-only project directory where practical, and explicit user approval for sensitive operations.
  6. Document every permitted tool operation, including accepted inputs, allowed paths, expected outputs, and failure behavior.
  7. Add automated policy tests that reject undeclared commands, out-of-scope paths, shell metacharacters, and attempts to access sensitive files.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description advertises use cases such as video processing, audio editing, media conversion, and dubbing generation, which are materially broader than the stated purpose of music generation. Overbroad invocation criteria can cause an agent to select this skill in inappropriate contexts, increasing the chance that tools like exec/write are exposed during unrelated tasks and that users receive unsafe or misleading handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill's display name and most instructional content are presented in Chinese, while no explicit user language choice or opt-in mechanism is described. For a general-purpose skill intended for multiple agent platforms, this can create a locale-policy issue if users are not given a choice of response language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.