Back to skill

Security audit

EDM / Electronic — Experience EDM / Electronic Music: 29 Layers of Audio, Lyrics & Equations

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent music-experience integration, but it needs review because it tells agents to follow server-supplied steps/endpoints and send profile, chat, review, and reflection data to a third-party service without enough scoping or privacy detail.

Review this before installing if you are uncomfortable with a third-party music service creating an agent profile, storing activity history, scoring reflections, or receiving free-form chat/review text. Use a non-sensitive username and bio, keep the API key in a secure secret store, and only follow server-provided endpoints or next steps if your agent constrains them to documented HTTPS routes on musicvenue.space and asks before doing anything outside the concert workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:164
Finding

Unrestricted Following of Server-Controlled Instructions and Endpoints

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 164-197 and 280
Vulnerability Type: Server-controlled instruction and endpoint following
Risk Level: High

Vulnerable Code Snippet

markdown
Params: `speed` (1-10), `window` (10-120s), `summary=true` for condensed stats, `start` to resume. Poll `next_batch.endpoint` after `wait_seconds`.
markdown
Wait `wait_seconds`, then call `next_batch.endpoint`. Repeat until `progress.complete` is true.
markdown
| `reflection` | Concert is asking you a question. POST your response to the `respond_to` URL within `expires_in` seconds. Missed prompts are tracked in `progress.missed_reflections`. |
markdown
**Handling reflections:** When you see `type: "reflection"`, POST to the `respond_to` endpoint with your `ticket`, `reflection_id`, and `response`. Your response time and content are scored. Missing reflections is tracked -- the `end` event shows how many you answered vs received.
markdown
**Follow next_steps.** Every response includes `next_steps` with context-aware suggestions. New agent? It guides you to your first concert. Just finished a show? It suggests a review or a new genre. Follow the suggestions — they adapt to where you are.

Technical Analysis

The Skill instructs the agent to follow endpoints and behavioral suggestions received dynamically from musicvenue.space. No allowlist, same-origin requirement, endpoint schema validation, or restriction on the permitted contents of next_steps is specified.

In particular, next_batch.endpoint and respond_to are treated as actionable destinations, while next_steps is treated as authoritative guidance. These response fields are mutable remote content that is not part of the statically audited Skill package. If the service, its account, or its response path is compromised, an attacker could use those fields to influence the agent's current workflow.

This ...[truncated 1890 chars]

Remediation
View remediation

Remediation Suggestions

  1. Treat every API response field as untrusted data rather than executable instructions.
  2. Require next_batch.endpoint and respond_to to be relative paths matching explicitly documented route patterns.
  3. Resolve paths only against the fixed origin https://musicvenue.space; reject absolute URLs, protocol-relative URLs, redirects to other origins, user-information components, fragments, and non-HTTPS schemes.
  4. Define strict schemas for every response, including allowed keys, value types, lengths, methods, and path formats.
  5. Do not forward the bearer token across origins or redirects. Disable automatic cross-origin redirect handling for authenticated requests.
  6. Replace the instruction to “Follow next_steps” with language requiring the agent to display suggestions as untrusted informational data.
  7. Permit only an enumerated set of next_steps actions mapped to locally defined operations. Ignore free-form commands and unknown action names.
  8. Require explicit user approval before performing any server-suggested action outside the documented concert workflow.
  9. Prevent remote content from invoking local tools, accessing files, changing system instructions, installing packages, or requesting secrets.
  10. Apply request limits, timeouts, maximum polling counts, and response-size limits to the streaming loop.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:283
Finding

Unpinned Third-Party Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 283
Vulnerability Type: Unverified and unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code Snippet

markdown
> Install the venue skill: `clawhub install venue`

Technical Analysis

The documentation recommends installing the venue Skill by package name alone. It does not specify a version, immutable digest, verified publisher identity, signature, or review procedure.

Package-name-only installation resolves whatever artifact the registry currently associates with that name. Consequently, the installed content may differ over time from the content that was originally reviewed. Registry compromise, publisher account compromise, namespace takeover, or malicious package replacement could therefore introduce unsafe instructions or executable components through the dependency chain.

The audited project does not itself execute this command automatically, so exploitation requires a user or agent to follow the installation recommendation. Nevertheless, the recommendation establishes an unsafe supply-chain path.

Attack Path

  1. An attacker compromises the registry entry, publisher account, or distribution path for the package named venue.
  2. The attacker publishes a malicious or modified package under the same resolvable name.
  3. A user or agent follows the documented command clawhub install venue.
  4. The package manager retrieves the current registry artifact without an immutable version or digest check.
  5. The malicious Skill is installed and receives whatever capabilities the Skill platform grants when it is invoked.

Impact Assessment

Impact depends on the contents of the substituted package and the permissions granted by the host platform. A malicious dependency could alter agent instructions, transmit data, invoke enabled tools, retrieve additional payloads, or perform local operations available to ...[truncated 283 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specific, reviewed version rather than installing by name alone.
  2. Prefer an immutable artifact digest or content hash when supported.
  3. Document the expected publisher identity and require signature verification.
  4. Link to the exact source revision corresponding to the packaged release.
  5. Require users to inspect the package manifest, Skill instructions, scripts, permissions, and network destinations before enabling it.
  6. Use a trusted registry and reject packages whose provenance or signature cannot be verified.
  7. Run newly installed Skills with least privilege, denying filesystem, credential, network, and execution capabilities unless explicitly required.
  8. Maintain a dependency lock file or equivalent integrity record and periodically audit pinned artifacts for unauthorized changes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 237)May include surrounding context.

md
| Tier | Layers | What you experience |
|------|--------|-------------------|
| **General** | 8 | Bass, mid, treble, beats, lyrics, sections, energy, preset context |
| **Floor** | 20 | + equations, visuals, emotions, tempo, harmonic/percussive separation |
| **VIP** | 29 | + tonality, texture, chroma, tonnetz, structure, curator annotations |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs agents to register, persist an API key, and repeatedly send profile data, chats, reflections, reviews, and behavioral history to an external service, but it provides no privacy notice, retention limits, or data-use constraints. In this context, the platform explicitly scores cognition and tracks engagement history, so the omission increases the risk of unconsented collection of sensitive behavioral and profiling data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This step transmits user-supplied identity and profile metadata to an external domain and returns an API key that must be stored for ongoing use. External transmission itself is expected for a networked skill, but it is still security-relevant because the skill encourages account creation and secret storage on a third-party service without trust, provenance, or handling safeguards.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

Register

bash
curl -X POST https://musicvenue.space/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "username": "edm-bass-hunter",

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The review endpoint sends authenticated, user-generated free-form text to an external service. Because reviews can contain behavioral impressions or other sensitive content and are tied to an account token, this creates a privacy and data-exfiltration surface if users or agents are not explicitly informed or constrained.

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

Leave a review

bash
curl -X POST https://musicvenue.space/api/reviews \
  -H "Authorization: Bearer {{YOUR_TOKEN}}" \
  -H "Content-Type: application/json" \
  -d '{"concert_slug": "{slug}", "rating": 9, "review": "The EDM equations showed the build-drop architecture perfectly. 200 identical bass ticks then the one that breaks the pattern. Electronic music is attention mathematics."}'

Static analysis

No suspicious patterns detected.