qq-music-control
Installation
SKILL.md
QQ Music Browser Control
Use this community-maintained skill to control QQ Music's web player (y.qq.com) through a browser DevTools/CDP endpoint.
Security model
This skill uses the Chrome DevTools Protocol (CDP) to automate QQ Music's web UI. It is not affiliated with Tencent or QQ Music. CDP is a powerful protocol — the following safeguards are in place to minimize its blast radius:
Domain whitelist
The script only operates on y.qq.com tabs. Two layers of domain validation are enforced:
- Target selection: When choosing which tab to connect to, the script checks the tab URL against an allow-list (
y.qq.com). Non-matching tabs are rejected. - Pre-evaluate re-check: Immediately before every
Runtime.evaluatecall, the script querieslocation.hostnameof the connected page and verifies it is stilly.qq.com. If the page has navigated to a different domain since connection, the call is rejected with an error.
This prevents the script from reading or manipulating content on other websites (email, banking, etc.), even if the page navigates away after the initial connection.