Back to skill

Security audit

音乐

Security checks across malware telemetry and agentic risk

Overview

This is a single Markdown music skill with no executable files, but it asks for broad read, write, and command-execution authority without clear music-specific limits.

Review carefully before installing. This does not contain visible malicious code, but it gives an agent broad write and command-execution authority for a music skill. Only install it if you are comfortable constraining tool use yourself and can verify any commands, file changes, API keys, and external service calls before they run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented as a personal music tracker, but its documented capabilities expand into generic file handling, API usage, and command execution. That scope mismatch increases the chance that an agent or user will authorize actions far beyond the expected music use case, enabling misuse of local files or system resources under an innocuous label.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Advertising command execution for a music skill is dangerous because it creates an unnecessary path to run system-level actions unrelated to the stated purpose. In an agent environment, this can be abused to execute harmful commands, access local data, or chain with other capabilities for broader compromise.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The claim that risky code was removed conflicts with later documentation that still promotes command execution and discusses command-execution risk. This inconsistency can mislead reviewers and users into overtrusting the skill while privileged behavior remains available.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill uses broad, vague applicability language without clear activation boundaries or task constraints. In practice, ambiguous scope encourages overbroad use of available tools and makes it easier for the skill to be repurposed for actions outside the intended domain.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The markdown describes file writing, API integration, and command execution without clear user-facing warnings about their effects. That is dangerous because users may invoke the skill expecting benign music management while it can modify files, contact external services, or run commands with security consequences.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.