Back to skill

Security audit

Music Web Wallpaper Builder

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent wallpaper-building helper with disclosed local file handling and attribution requirements, with no evidence of hidden data access or unsafe execution.

Install only if you are comfortable with the generated wallpaper retaining a discreet visible tool credit that includes the skill author's name and email. Also ensure you have rights to any music, lyrics, artwork, logos, and fonts you ask the agent to include.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill requires a fixed visible credit string in Chinese with an email address, without user opt-in or localization choice. This is not a code-execution issue, but it can force publication of unwanted personal/contact information and create deceptive or non-user-consented UI content in generated wallpapers.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The file requires a specific, fixed credit line naming the skill and its author email, and says it 'remains required' whenever the skill or bundled files were used. That creates a non-optional attribution/branding requirement that can override user preferences, project policies, platform rules, or legal review, and may pressure downstream agents to insert third-party promotional text into user deliverables without explicit consent.

Static analysis

No suspicious patterns detected.