Back to skill

Security audit

music-practice-buddy

Security checks for vulnerabilities and agentic risk

Overview

This skill performs local music-recording analysis and writes local practice-history files that are aligned with its progress-tracking purpose, though users should know that analyses are logged.

Install only if you are comfortable with the tool keeping a local practice history. Before using it on private recordings or a shared machine, consider reviewing or deleting artifact/practice_log.json periodically and saving optional JSON reports only in locations you control. For reproducible installs, pin numpy to a known version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
README.md:91
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, line 91
Vulnerability Type: Unpinned third-party dependency
Risk Level: Low

bash
pip install numpy

Technical Analysis

The installation instructions resolve numpy without a version constraint, lockfile, or cryptographic hash. Consequently, installations performed at different times may retrieve different package releases. This weakens build reproducibility and prevents users from verifying that the installed artifact is the dependency version reviewed and tested with this project.

The package name refers to the expected public dependency, and the project does not use an apparent typosquatted name or an untrusted package index. Exploitation therefore requires the selected package source or a subsequently resolved release to be compromised. This is a supply-chain hardening issue rather than evidence that the current dependency is malicious.

Attack Path

  1. A user follows the installation command from README.md.
  2. pip resolves the latest compatible numpy distribution from the configured package index.
  3. If that index, the package release, the user's package-index configuration, or the distribution artifact has been compromised, an attacker-controlled artifact is downloaded.
  4. Malicious behavior may execute during package installation or when the application later imports numpy.
  5. The payload runs with the privileges of the user performing the installation or launching the application.

Impact Assessment

A successful supply-chain compromise could execute arbitrary code under the installing user's account. This could expose files and credentials accessible to that account, modify user-owned data, or affect subsequent application execution. System-wide impact would require the user to install the dependency with elevated privileges; the documented command itself does not request elevation. No direct dependency compromise, remote payl ...[truncated 90 chars]

Remediation
View remediation

Remediation Suggestions

  • Declare an explicitly tested numpy version or bounded compatible version range.
  • Generate and commit a lockfile containing exact transitive dependency versions.
  • Require cryptographic hashes for installation artifacts, for example through a hash-locked requirements file and pip install --require-hashes.
  • Install from the official Python Package Index or a controlled internal mirror, and document the expected package source.
  • Integrate dependency vulnerability and integrity scanning into the release process.
  • Avoid recommending installation with administrator or root privileges.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Context Leakage

High
Category
Data Exfiltration
Confidence
88% confidence
Finding

The analysis result, including timestamps, source filename, detailed scores, and tempo-related data, is automatically persisted beyond the immediate task scope. In a local assistant skill, this is a form of context retention that may leak user activity patterns or sensitive filenames to anyone with access to the host or synced storage.

Content

Scanner excerpt · scripts/practice_buddy.py (reported line 525)May include surrounding context.

python
"target_bpm_comparison": target_comparison,
    }

    # Log the session
    log_session(result)

    return result

Context Leakage

High
Category
Data Exfiltration
Confidence
89% confidence
Finding

The dedicated logging function creates a persistent store of prior analyses without access control, retention limits, or user consent flow. Even though the data is not highly sensitive in all cases, it can still reveal habits, timestamps, and practice file names, making this a genuine privacy and context-leakage issue.

Content

Scanner excerpt · scripts/practice_buddy.py (reported line 651)May include surrounding context.

python
def log_session(result):
    """Log the session to practice_log.json."""
    log = []
    if os.path.exists(PRACTICE_LOG):
        try:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill documentation advertises commands and workflows that can generate reports, plans, and history, and the static analyzer detected file-writing capability, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates a least-privilege gap: downstream agents or runners may permit broader filesystem access than users expect, increasing the risk of unintended file creation or overwrite if the implementation writes logs, reports, or history data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Every analysis is automatically written to a persistent local log without explicit notice or consent, creating silent retention of user activity and file-derived metadata. This can expose practice history, timestamps, filenames, and performance metrics to other local users, backups, or tools that access the filesystem, especially on shared machines.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes audio analysis and report generation for instrumental practice feedback, which implies processing a provided recording and returning feedback. The code additionally writes persistent session history to practice_log.json for every analysis, creating stored user activity data that is not mentioned in the manifest description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Persistently storing timestamps, filenames, scores, and BPM across sessions enables history tracking beyond the core function of analyzing a recording and producing practice feedback. While related, this retention capability is separate from immediate analysis and is not stated in the manifest's purpose statement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The code writes the full analysis result to the path provided by --output, which persists recording-derived metadata and scores. While this is user-triggered, the CLI argument help does not describe the nature of the saved data, and there is no prior disclosure beyond the post-write success message.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.