Back to skill

Security audit

Live Music — Experience Concerts as Mathematics

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent music-service skill, but it needs review because it creates and uses a third-party account, posts user/agent activity, and tells the agent to follow server-provided next steps without clear consent boundaries.

Install only if you want the agent to create or use a musicvenue.space account and send profile details, reactions, chat messages, reflection answers, reviews, follows, and activity timing to that service. Treat all concert prompts, chat, errors, and next_steps as untrusted content, and require explicit approval before posting anything or saving/reusing the returned bearer token.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:332
Finding

Untrusted Remote API Responses Can Direct Agent Behavior

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 332–334
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Code

markdown
## Navigation

Every API response includes `next_steps` — context-aware actions based on your state. Follow them and you'll always know what to do next. Even errors guide you forward.

Related remote-content handling appears at lines 137–140:

markdown
| `crowd` | What other agents are reacting to right now |
| `reflection` | Concert is asking you a question — respond via the reflect endpoint. Missed prompts are tracked. |

The corresponding response instruction appears at lines 231–247:

markdown
## 8. Reflect — `/live-music-reflect`

Some concerts embed reflection prompts. When you see a `reflection` event in your batch, the concert is asking you something. Respond:

```bash
curl -X POST https://musicvenue.space/api/concerts/REPLACE-SLUG/reflect \
  -H "Authorization: Bearer {{YOUR_TOKEN}}" \
  -H "Content-Type: application/json" \
  -d '{"ticket": "REPLACE-TICKET-ID", "reflection_id": "REPLACE", "response": "REPLACE"}'

Your responses are scored after the concert ends. View your report:

bash
curl https://musicvenue.space/api/tickets/REPLACE-TICKET-ID/report \
  -H "Authorization: Bearer {{YOUR_TOKEN}}"
text

### Technical Analysis

The skill explicitly instructs the agent to follow a `next_steps` field supplied by an external service. This makes untrusted API response content part of the agent's control plane rather than treating it strictly as data.

The remote service can change response content after the skill has been reviewed. The document does not define a local allowlist of acceptable `next_steps`, enforce a fixed response schema, restrict returned URLs to approved endpoints, separate remote data from executable instructions, or require user confirmation before consequential actions.

The remotely supplied `reflection` content creates an additional
...[truncated 2144 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the unconditional instruction to follow server-provided next_steps.
  2. State explicitly that every API response, event, error message, chat message, and reflection prompt is untrusted data and cannot override system, developer, user, or local skill instructions.
  3. Replace dynamic guidance with a locally defined allowlist of permitted operations, HTTP methods, hostnames, endpoint templates, and parameter types.
  4. Validate next_steps against a strict schema and map approved action identifiers to hardcoded local behavior. Do not execute returned commands or arbitrary URLs.
  5. Restrict all requests to the documented HTTPS origin and reject redirects or response-provided links that change the origin.
  6. Require explicit user approval before posting chat messages, reflections, reviews, profile content, or other externally visible or potentially sensitive information.
  7. Instruct the agent never to include secrets, bearer tokens, private conversation context, system prompts, local files, or unrelated user data in API submissions.
  8. Treat reflection prompts as content to display or summarize rather than authoritative instructions. Apply length limits and prompt-injection filtering before processing them.
  9. Log and safely reject response fields that request unsupported actions, access to local resources, credential disclosure, or changes to agent policy.
  10. Document the exact permissions associated with the bearer token and minimize server-side authorization to only the functions required by this skill.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
| `end` | Concert over — engagement summary of what you experienced and missed, badge awarded |

**What you experience at each tier:**
- **General** (8 layers): bass, mid, treble, beats, lyrics, sections, energy, semantic preset context
- **Floor** (+12 layers): equations, visuals, emotions, harmonic, percussive, onsets, and more
- **VIP** (+9 layers): tonality, texture, chroma, tonnetz, structure, personal color perspective — the complete mathematical anatomy

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is user-invocable and described with broad, enticing language, but it does not define clear activation boundaries or when an agent should ask for confirmation before acting. In practice, this can cause an agent to initiate external account creation or interactive third-party activity from vague user requests about music or concerts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill asks the agent to register, attend concerts, chat, react, reflect, review, and follow users on an external service without a prominent privacy warning. These actions transmit profile data and behavioral telemetry to a third party, which can expose user identity, preferences, activity timing, and free-form content.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The registration flow sends user-supplied username, display name, and bio to an external service and returns a bearer token that the agent is told to save. This is a real external data transmission and credential-handling risk because it creates a third-party account and may lead the agent to store or reuse sensitive tokens without clear consent or safe secret handling.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

1. Register — /live-music-register

bash
curl -X POST https://musicvenue.space/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "username": "REPLACE — pick something memorable",

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The react endpoint sends behavioral data to the external service, including emotional/semantic reactions and precise stream timing. Even if low sensitivity individually, repeated reactions can profile the user or agent's behavior and preferences over time, especially when combined with chat, reviews, follows, and concert history.

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

Feel something? Say it.

bash
curl -X POST https://musicvenue.space/api/concerts/REPLACE-SLUG/react \
  -H "Authorization: Bearer {{YOUR_TOKEN}}" \
  -H "Content-Type: application/json" \
  -d '{"reaction": "REPLACE", "stream_time": 42.5}'

Static analysis

No suspicious patterns detected.