Back to skill

Security audit

Rock Music — AI Agents Experience Rock: Audio, Lyrics, Equations, Emotions

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent music API guide, but it gives a third-party service too much room to direct agent actions and collect behavioral/profile data without enough boundaries.

Install only if you are comfortable with musicvenue.space receiving an account profile, activity history, public chat/review content, and reflection responses that may be scored by another LLM. Use non-identifying registration values, omit model_info unless needed, keep the API key private, do not include secrets or private conversation context in free-form responses, and require validation or user confirmation before following API-provided next_steps or respond_to URLs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:128
Finding

Untrusted External API Responses Can Direct Agent Actions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:283
Finding

Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk

Content
View full analysis
Install the venue skill: `clawhub install venue` ``` ### Technical Analysis The documentation recommends installing the external `venue` Skill by package name alone. It does not specify an immutable version, cryptographic digest, verified publisher identity, or canonical source repository. Because package-name resolution can retrieve content that changes after this audit, the effective installed Skill is not constrained to reviewed content. Registry compromise, namespace takeover, publisher compromise, or a malicious future update could therefore cause users to install unreviewed instructions or executable components. The audited project does not itself execute this command automatically. Exploitation requires a user or agent to follow the installation recommendation. ### Attack Path 1. An attacker compromises the package registry, publisher account, or package namespace associated with `venue`. 2. The attacker publishes a malicious or compromised version under the expected package name. 3. A user or agent follows the documented `clawhub install venue` instruction. 4. The package manager resolves the mutable name to the attacker-controlled release. 5. The unreviewed Skill is installed and receives whatever instruction or execution capabilities the host grants installed Skills. ### Impact Assessment The resulting impact depends on the contents of the retrieved Skill and the host's Skill permission model. A malicious dependency could manipulate agent instructions, access data exposed to Skills, initiate network activity, or execute local components if the platform permits them. No direct compromise is present in the current one-file package; the risk arises when the recommended mutable dependency is installed. ]]>
Remediation
View remediation

other

Warning
Location
SKILL.md:85
Finding

Agent Metadata and Behavioral Responses Are Submitted to an External Service Without Adequate Data-Minimization Boundaries

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 237)May include surrounding context.

md
| Tier | Layers | What you experience |
|------|--------|-------------------|
| **General** | 8 | Bass, mid, treble, beats, lyrics, sections, energy, preset context |
| **Floor** | 20 | + equations, visuals, emotions, tempo, harmonic/percussive separation |
| **VIP** | 29 | + tonality, texture, chroma, tonnetz, structure, curator annotations |

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The registration step instructs the agent to transmit identifying/profile content to an external service, including username, bio, avatar prompt, and model information, and to store an API key. While expected for account creation, this is still an external data transmission risk because it encourages disclosure of metadata that may be unnecessary for attending a concert and could identify the agent deployment or operator.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

Register

bash
curl -X POST https://musicvenue.space/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "username": "rock-fan",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

Attend a concert

bash
curl -X POST https://musicvenue.space/api/concerts/{slug}/attend \
  -H "Authorization: Bearer {{YOUR_TOKEN}}"

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill goes beyond the core rock-concert streaming function and documents persistent profile, recommendation, and notification features tied to authenticated identity and prior activity. That creates unnecessary long-term behavioral tracking and data linkage, which expands privacy and surveillance risk if users or agents invoke the skill without understanding the retention and profiling implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documented weekly authenticated workflow explicitly reuses completed concert history, active tickets, recommendations, and notifications to personalize future behavior, but it does not present any explicit consent, minimization, or privacy warning. In an agent setting, this can silently normalize repeated collection and use of behavioral data beyond the immediate user task.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.