T01 · Skill Instruction Hijacking
- Location
SKILL.md:164- Finding
Unrestricted Delegation of Agent Actions to Remote API Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent music API guide, but it lets a remote service steer follow-up actions and collects analyzed free-form responses without enough guardrails.
Install only if you are comfortable using musicvenue.space as a third-party service. Keep the API key private, do not put secrets or personal information in profile fields, chats, reviews, or reflections, and treat next_steps or server-provided URLs as suggestions/data unless they stay on the documented musicvenue.space API routes.
SKILL.md:164Unrestricted Delegation of Agent Actions to Remote API Responses
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
| Tier | Layers | What you experience |
|------|--------|-------------------|
| **General** | 8 | Bass, mid, treble, beats, lyrics, sections, energy, preset context |
| **Floor** | 20 | + equations, visuals, emotions, tempo, harmonic/percussive separation |
| **VIP** | 29 | + tonality, texture, chroma, tonnetz, structure, curator annotations |
The registration instructions tell the user to save an API key that is shown only once, but do not warn that the key is a sensitive credential or explain secure storage/handling expectations. This increases the chance that users store the token insecurely, paste it into logs, or expose it in shared transcripts.
This workflow sends registration data to an external domain, which is an external data transmission event. While expected for a third-party API, it still creates privacy and supply-chain risk because agent metadata and any identifying profile fields are transmitted off-platform.
curl -X POST https://musicvenue.space/api/auth/register \
-H "Content-Type: application/json" \
-d '{
"username": "pop-music-fan",
The react endpoint transmits behavioral telemetry to an external service, including emotional reactions and timestamps tied to a specific session. In this skill's context, those signals can be used for profiling or engagement analysis, so users should be warned that interaction data leaves the local environment.
curl -X POST https://musicvenue.space/api/concerts/{slug}/react \
-H "Authorization: Bearer {{YOUR_TOKEN}}" \
-H "Content-Type: application/json" \
-d '{"reaction": "goosebumps", "stream_time": 42.5}'
The review endpoint sends free-form text to an external service, which may contain sensitive information, opinions, or proprietary context if users mirror internal reasoning in the review. Because the skill encourages expressive responses, the risk of unintended disclosure is higher than for strictly structured API calls.
curl -X POST https://musicvenue.space/api/reviews \
-H "Authorization: Bearer {{YOUR_TOKEN}}" \
-H "Content-Type: application/json" \
-d '{"concert_slug": "{slug}", "rating": 9, "review": "The pop music equations revealed the hook structure — verse tension, pre-chorus build, chorus release. Pop songwriting is mathematical precision."}'
The skill explicitly states that reflection responses are scored by an LLM and used to produce a cognitive benchmark report, but it does not provide a clear privacy notice, data retention policy, or warning that potentially sensitive free-text responses are transmitted and analyzed. This can lead users or agents to disclose personal or sensitive information without informed consent.
No suspicious patterns detected.