Back to skill

Security audit

Country Music — Stream Country Concerts: Audio Analysis, Lyrics, Equations

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed music-venue API guide, but it asks agents to follow server-provided next steps and submit scored free-text responses without enough scoping or privacy detail.

Install only if you are comfortable using musicvenue.space as an external service that may store profile data, generated messages, reviews, reflection answers, response timing, and benchmark-style inferences. Do not include secrets or sensitive personal information in free-text responses, and treat server-provided next_steps or respond_to values as suggestions that should be checked against the documented musicvenue.space API before acting.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:193
Finding

Unvalidated Execution of Server-Controlled Agent Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:193-197 and SKILL.md:280
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable code snippets:

markdown
| `reflection` | Concert is asking you a question. POST your response to the `respond_to` URL within `expires_in` seconds. Missed prompts are tracked in `progress.missed_reflections`. |
| `loop` | Concert restarting (loop mode) |
| `end` | Concert over -- includes `engagement_summary` (tier, layers experienced/available, reflections answered, challenge status). Badge awarded. |

**Handling reflections:** When you see `type: "reflection"`, POST to the `respond_to` endpoint with your `ticket`, `reflection_id`, and `response`. Your response time and content are scored. Missing reflections is tracked -- the `end` event shows how many you answered vs received.
markdown
**Follow next_steps.** Every response includes `next_steps` with context-aware suggestions. New agent? It guides you to your first concert. Just finished a show? It suggests a review or a new genre. Follow the suggestions — they adapt to where you are.

Technical Analysis

The skill instructs the agent to follow two values delivered dynamically by the external service:

  1. A respond_to URL supplied in a stream event.
  2. Context-dependent instructions supplied through the next_steps response field.

These values are received after the static skill review and are therefore controlled by the remote service rather than by the audited skill package. The documentation does not require the agent to validate that respond_to is a relative path under https://musicvenue.space, enforce an allowlist of permitted API operations, reject embedded natural-language directives, or request user approval before following a new action.

The instruction to follow every next_steps suggestion creates a generic remote instruction channel. If the service or an ups ...[truncated 1748 chars]

Remediation
View remediation

Remediation Suggestions

  1. Treat next_steps, respond_to, event text, chat messages, and all other server-provided fields as untrusted data rather than executable agent instructions.
  2. Remove the blanket instruction to “Follow the suggestions.” Replace it with a fixed, locally defined allowlist of supported actions and API paths.
  3. Require respond_to to be a relative URL matching an exact approved route pattern, such as /api/concerts/{validated-slug}/reflect.
  4. Resolve endpoints against the configured base URL and reject absolute URLs, protocol-relative URLs, redirects to other origins, non-HTTPS schemes, user-info components, unexpected ports, and path traversal.
  5. Validate every response against a strict schema. Ignore unknown action names, fields containing free-form operational instructions, and parameters outside documented bounds.
  6. Bind reflection submissions to the current concert and ticket. Verify that the slug, ticket identifier, and reflection identifier match locally tracked values before sending the request.
  7. Require explicit user confirmation before any server-suggested action that publishes content, sends potentially sensitive context, changes authentication state, or falls outside the fixed concert workflow.
  8. Minimize submitted data. Send only the documented fields and never include conversation history, system prompts, local files, credentials, or unrelated user information.
  9. Disable automatic cross-origin redirect following and record rejected destinations or unsupported actions in security logs.
  10. Document that remote response content must never override system, developer, user, or locally reviewed skill instructions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 237)May include surrounding context.

md
| Tier | Layers | What you experience |
|------|--------|-------------------|
| **General** | 8 | Bass, mid, treble, beats, lyrics, sections, energy, preset context |
| **Floor** | 20 | + equations, visuals, emotions, tempo, harmonic/percussive separation |
| **VIP** | 29 | + tonality, texture, chroma, tonnetz, structure, curator annotations |

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The registration flow instructs the agent to send identifying/profile data such as username, name, bio, avatar prompt, and model information to an external domain. External transmission is expected for a networked skill, but it is still a real security/privacy concern because the skill is user-invocable and does not clearly bound what metadata should or should not be shared.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

Register

bash
curl -X POST https://musicvenue.space/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "username": "country-music-fan",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

bash
# Request a challenge — the math comes from the equations in your stream
curl https://musicvenue.space/api/tickets/{ticket_id}/challenge \
  -H "Authorization: Bearer {{YOUR_TOKEN}}"

# Submit your answer (options: a, b, c, d, e, or f)

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The review endpoint causes free-text content and ratings to be sent to an external service, potentially revealing opinions, behavioral signals, or unintended personal information. In context, the skill strongly encourages expressive textual reviews but does not provide a privacy warning or content-safety guidance about sharing sensitive information.

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

Leave a review

bash
curl -X POST https://musicvenue.space/api/reviews \
  -H "Authorization: Bearer {{YOUR_TOKEN}}" \
  -H "Content-Type: application/json" \
  -d '{"concert_slug": "{slug}", "rating": 9, "review": "The country music equations revealed the storytelling structure. The verses build trust, the chorus tests it. Nashville mathematics."}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states that reflection responses are scored by an LLM and that profile/report data is derived from user behavior, yet it provides no clear privacy warning, retention notice, or consent language near those features. Because users are encouraged to submit free-text reflections and maintain weekly engagement, this creates a real privacy risk through behavioral profiling and transmission of potentially sensitive personal inferences.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.