Back to skill

Security audit

音乐

Security checks for vulnerabilities and agentic risk

Overview

This music-tracking skill is Markdown-only, but it asks for command execution and file-writing authority that is not clearly bounded by its music purpose.

Review before installing. This does not show malicious payloads, persistence, or exfiltration, but it gives a music-themed skill broad write and command-execution authority. Install only if you trust the publisher and are comfortable with the agent using local files, external APIs, and shell commands; otherwise ask the publisher to remove exec/write or document exact allowed actions first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Requesting the exec tool in the manifest grants the skill direct command-execution capability despite the stated purpose being music tracking and organization. That mismatch is especially risky because tool permissions are what determine real power, and an attacker or confused user could leverage exec for actions far outside the expected music workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Declaring system command execution for a music-management skill is dangerous because exec enables arbitrary local actions unrelated to the stated purpose. In this context, the capability is not clearly justified, so it expands the attack surface for filesystem access, persistence, or host compromise if the skill is invoked with unsafe instructions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill uses broad applicability language spanning personal management, automation workflows, and decision support without clear trigger constraints or boundaries. Overbroad positioning makes it easier to justify unrelated or risky operations under vague intent, especially when the skill also has write and exec capabilities.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description claims risky code and external-risk elements were removed, yet the skill still exposes command execution capability. This contradiction can mislead reviewers and users into underestimating risk, which is itself security-relevant because it weakens informed consent and scrutiny around a high-risk permission.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a personal music tracking tool, but the documentation advertises generic file handling, API access, and command execution capabilities that materially exceed that scope. This mismatch increases the chance the skill could be used as a general-purpose execution wrapper, reducing user awareness and making unsafe actions appear legitimate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown advertises file writing, API integration, and command execution but does not provide strong user-facing warnings about the security impact of those actions. In a skill with elevated capabilities, insufficient disclosure increases the risk of unsafe use, accidental data modification, or trust abuse because users may assume the tool is low-risk based on its music theme.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.