Back to skill

Security audit

sense-music

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local audio-analysis skill with privacy and package-provenance caveats, but the inspected artifacts do not show deception, exfiltration, persistence, or destructive behavior.

Install only if you are comfortable relying on the current PyPI package and its dependencies; prefer pinning a reviewed version in controlled environments. Treat audio files and generated lyrics/transcripts/HTML/JSON/images as potentially sensitive, disable lyrics for private recordings, and delete exported outputs or cached models when they are no longer needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned and Unauditable Third-Party Package Installation

Content
View full analysis
**Install:** `pip install sense-music` then `from sense_music import analyze` ``` `metadata.json:8`: ```json "install": "pip install sense-music", ``` `metadata.json:19-23`: ```json "dependencies": { "librosa": ">=0.10", "matplotlib": ">=3.7", "Pillow": ">=10.0", "numpy": ">=1.24", "openai-whisper": ">=20231117" }, ``` ### Technical Analysis The skill installs `sense-music` from the public Python package index without an exact version or integrity hash. Its listed dependencies also use open-ended lower-bound constraints, allowing later package versions to be selected at installation time. The audited project contains only documentation, metadata, and a six-line usage example. It does not contain the implementation of the imported `sense_music` package. Therefore, the actual code executed by installation and import cannot be audited from this artifact, and the documented SSRF, path-traversal, XSS, and resource-limit protections cannot be independently verified here. Because package resolution is mutable, two installations reviewed at different times can retrieve different code. A compromise of the `sense-music` distribution, one of its dependencies, or the relevant package-publishing accounts could introduce code that was not present during this review. ### Attack Path 1. An attacker compromises a maintainer or package-publishing account for `sense-music` or one of its dependencies and publishes a malicious compatible release. 2. An operator follows `pip install sense-music`, or the skill manager processes the unpinned `uv` installation declaration. 3. The package resolve ...[truncated 1070 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents lyrics transcription and local caching/output generation, but it does not clearly warn operators that user-provided audio may contain sensitive spoken or sung content and that derived artifacts such as transcripts, HTML, JSON, and images may be stored locally. This can lead to unintentional collection, retention, or sharing of personal or confidential information, especially when analyzing recordings that contain conversations, names, or copyrighted/private material.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.