Back to skill

Security audit

Byted Music Generate

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate Volcengine music-generation skill, but it sends prompts or lyrics to Volcengine and may use paid API billing.

Before installing, make sure users understand that prompts, lyrics, and generation settings are sent to Volcengine and that song or BGM generation defaults to postpaid billing. Use a dedicated, least-privilege Volcengine key with spending limits, avoid submitting sensitive or proprietary lyrics unless acceptable under Volcengine's terms, and do not store keys in a shared workspace file.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger conditions are broad enough to activate on ordinary discussion of music, lyrics, or songwriting, increasing the chance the skill runs when the user did not intend external API use. In this context, accidental invocation matters because the skill can transmit user-provided creative content to a third-party service and may incur cost.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill description does not clearly warn that prompts and lyrics are sent to an external API provider. That creates a privacy and consent risk because users may share sensitive or proprietary text believing it stays local, while the skill is designed to upload it for processing.

Static analysis

No suspicious patterns detected.