Back to skill

Security audit

ace-music组合包

Security checks across malware telemetry and agentic risk

Overview

This creative bundle is documentation-only, but it asks for broad command, file, and API capabilities without clearly scoping how they are used.

Review before installing. Treat this as a broad-capability bundle: only use it in a contained workspace, do not provide API keys unless you know exactly which member skill needs them, and confirm any file writes or command execution before allowing them. I found no evidence of intentional exfiltration, destructive behavior, or hidden persistence.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The skill is presented as a creative music bundle, but later advertises generic file handling, API integration, and command execution capabilities that materially expand its effective attack surface beyond the stated purpose. This mismatch can mislead users and reviewers into granting broad trust or permissions to a bundle that may invoke higher-risk behaviors such as external calls or local command execution.

Intent-Code Divergence

Medium
Confidence
86% confidence
Finding
The document states that no external API is required, but later instructs users to configure API keys and establish API connections. This inconsistency can cause users to expose credentials unnecessarily or misunderstand where data is being sent, undermining informed consent and secure deployment decisions.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill describes writing files, calling APIs, and executing system commands, but does not provide concrete warnings or operational constraints around credential exposure, destructive file writes, command safety, or integrity risks. In a bundle that already has broad tools listed including exec and write, omission of these warnings increases the chance of unsafe use and accidental system or data compromise.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.