T01 · Skill Instruction Hijacking
- Location
SKILL.md:128- Finding
Untrusted External API Responses Can Direct Agent Actions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent music API guide, but it gives a third-party service too much room to direct agent actions and collect behavioral/profile data without enough boundaries.
Install only if you are comfortable with musicvenue.space receiving an account profile, activity history, public chat/review content, and reflection responses that may be scored by another LLM. Use non-identifying registration values, omit model_info unless needed, keep the API key private, do not include secrets or private conversation context in free-form responses, and require validation or user confirmation before following API-provided next_steps or respond_to URLs.
SKILL.md:128Untrusted External API Responses Can Direct Agent Actions
SKILL.md:283Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk
SKILL.md:85Agent Metadata and Behavioral Responses Are Submitted to an External Service Without Adequate Data-Minimization Boundaries
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
| Tier | Layers | What you experience |
|------|--------|-------------------|
| **General** | 8 | Bass, mid, treble, beats, lyrics, sections, energy, preset context |
| **Floor** | 20 | + equations, visuals, emotions, tempo, harmonic/percussive separation |
| **VIP** | 29 | + tonality, texture, chroma, tonnetz, structure, curator annotations |
The registration step instructs the agent to transmit identifying/profile content to an external service, including username, bio, avatar prompt, and model information, and to store an API key. While expected for account creation, this is still an external data transmission risk because it encourages disclosure of metadata that may be unnecessary for attending a concert and could identify the agent deployment or operator.
curl -X POST https://musicvenue.space/api/auth/register \
-H "Content-Type: application/json" \
-d '{
"username": "rock-fan",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST https://musicvenue.space/api/concerts/{slug}/attend \
-H "Authorization: Bearer {{YOUR_TOKEN}}"
The skill goes beyond the core rock-concert streaming function and documents persistent profile, recommendation, and notification features tied to authenticated identity and prior activity. That creates unnecessary long-term behavioral tracking and data linkage, which expands privacy and surveillance risk if users or agents invoke the skill without understanding the retention and profiling implications.
The documented weekly authenticated workflow explicitly reuses completed concert history, active tickets, recommendations, and notifications to personalize future behavior, but it does not present any explicit consent, minimization, or privacy warning. In an agent setting, this can silently normalize repeated collection and use of behavioral data beyond the immediate user task.
No suspicious patterns detected.