Back to skill

Security audit

Xiao Chuang You Music

Security checks across malware telemetry and agentic risk

Overview

This is a simple Chinese-style music recommendation skill with broad activation terms but no code, credentials, persistence, or system access.

Safe to install based on the provided artifacts. Expect it to steer general music requests toward Chinese-style and traditional music recommendations; users with overlapping music skills may want narrower activation terms to reduce accidental invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation list includes many generic terms such as “音乐”, “推荐音乐”, “背景音乐”, and “听什么”, which are common in ordinary conversation and can cause the skill to trigger outside its intended niche. Over-broad triggers increase routing collisions and prompt-scope confusion, which can lead to unintended invocation and make downstream behavior easier to manipulate or misapply.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.