Back to skill

Security audit

音乐

Security checks across malware telemetry and agentic risk

Overview

This music skill is not clearly malicious, but it asks for broad command, file, and API authority that is not well scoped to music tracking.

Review this skill before installing. It may be usable for music organization, but only if you are comfortable granting broad local file, command execution, and unspecified API access; prefer a version that limits operations to explicit music files and named music services.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill manifest and description present a narrow music-tracking purpose, but the documentation expands into generic automation and execution-oriented capabilities. This scope drift is dangerous because it can justify broader tool use than users or reviewers expect, increasing the chance that powerful tools are invoked under misleading pretenses.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The core-function section claims broad life-management, habit-building, and workflow decision-support features that do not match a music skill. Such contradictory positioning can conceal real operational scope and encourage overbroad trust or permissioning by an agent platform.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The documentation explicitly advertises system command execution even though the stated purpose is personal music management. In this context, command execution is an unnecessary high-risk capability that could be abused to run arbitrary shell commands, access local data, or pivot into broader system actions.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
The skill claims generic file read/write capability without tying it to specific music-management functions. Broad file access expands the blast radius of misuse, potentially exposing or modifying unrelated local files under the cover of a benign-seeming music tool.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The skill advertises external API integration as a general capability without explaining which music-related services are used or why. Unbounded API access can enable data exfiltration, interaction with unintended services, or trust confusion about what external systems the skill may contact.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The description claims that risky code and external dependencies were removed, yet later sections still promote command execution and API capabilities as core features. This is a red flag because self-attestation of safety while retaining risky functionality can mislead reviewers and users into underestimating the true attack surface.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.