Back to skill

Security audit

音乐

Security checks for vulnerabilities and agentic risk

Overview

This music skill is Markdown-only and shows no malware, but it asks for broad file and command authority that is not clearly scoped to music generation.

Review this skill before installing. It does not contain an executable payload, but its declared read/write/exec authority is broader than its music-generation documentation justifies. Prefer installing only after the tool list is minimized or the author documents exact file scopes, allowed commands, and user-confirmation rules.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:36
Finding

Excessive Tool Permissions Violate Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 36–39
Vulnerability Type: Excessive filesystem and command-execution permissions
Risk Level: Medium

Vulnerable Code

yaml
tools:
  - read
  - exec
  - write

Technical Analysis

The skill declares filesystem read, filesystem write, and command-execution capabilities, although the package contains only a Markdown instruction file and provides no implementation demonstrating a legitimate need for these privileges. Prompt optimization and music-generation guidance do not inherently require unrestricted local filesystem access or operating-system command execution.

This violates the principle of least privilege. In an Agent platform that grants capabilities according to this declaration, the skill would have a broader authority boundary than its documented purpose requires. The file also identifies the skill as MD+execute() at line 133, but it defines no executable workflow that justifies command execution.

No direct malicious command, credential theft, persistence mechanism, or data-exfiltration instruction was found. The vulnerability is the unnecessary exposure of privileged tools, which creates an exploitable capability if untrusted contextual instructions influence subsequent Agent behavior.

Attack Path

  1. An Agent loads the skill and grants the declared read, write, and exec tools.
  2. The Agent processes attacker-controlled content, a malicious prompt, or another untrusted contextual instruction during the skill session.
  3. That content induces the Agent to invoke one of the unnecessarily available tools.
  4. The Agent reads sensitive local files, modifies accessible data, or executes a local command under the permissions of the hosting process.
  5. The resulting confidentiality, integrity, and potentially availability impact extends to resources accessible by the Agent account.

Impact Assessment

Successful explo ...[truncated 587 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove exec, read, and write from the tool declaration unless each capability is essential to a concrete, documented workflow.
  2. Prefer a dedicated music-generation API tool with a narrow schema instead of general-purpose command execution.
  3. If file access is required, restrict it to explicit input and output directories and reject path traversal, symbolic-link escapes, and access to credentials or configuration files.
  4. If command execution becomes essential, use a sandbox with an explicit command and argument allowlist. Never construct shell commands from user-controlled input.
  5. Require user confirmation for sensitive reads, writes, destructive operations, and command execution.
  6. Run the Agent under a minimally privileged operating-system account with network, filesystem, process, and resource restrictions.
  7. Update the MD+execute() classification and documentation so they accurately reflect the final, minimized capability set.
  8. Add security tests confirming that untrusted prompts cannot trigger access outside approved resources.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Advertising system command execution for a music-generation skill is dangerous because it grants a powerful primitive unrelated to the stated purpose. In an agent context, this can enable arbitrary local actions, data access, or chaining with user-controlled inputs, turning a creative skill into a general execution pathway.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The claim that 'original risk code was removed' conflicts with later sections that still promote execution-related behavior and risks. Such contradictory assurances are a red flag because they may reduce reviewer caution while preserving dangerous capabilities, making accidental trust and unsafe deployment more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Overly broad invocation guidance without concrete triggers or boundaries can cause the skill to activate in unintended contexts. When combined with read/write/exec tooling, ambiguous activation materially raises the chance that unrelated user requests will be interpreted as permission to perform sensitive operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documentation describes generic file-processing and command-execution behavior that does not align with a music-generation skill. This broadens the apparent capability surface and can mislead an agent into performing unintended read/write/exec actions under the pretext of music generation, increasing the risk of prompt-induced misuse or privilege abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The user-facing metadata and description present a mixed-language experience, with Chinese display text and summaries that also include English content, but there is no statement that users can choose their preferred language. This can create a language/locale policy issue if the skill defaults to a specific presentation style without explicit user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.