qqmusic

Warn

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to modify system configuration files (~/.bashrc and ~/.zshrc) to persist the QQMUSIC_API_KEY. This persistence mechanism alters the user's shell environment by appending or substituting export commands.
  • [EXTERNAL_DOWNLOADS]: The skill documents a 'Skill Upgrade' feature in version.md that involves checking for updates via an API and then downloading and replacing skill files. While the instructions limit downloads to vendor-controlled domains (y.qq.com or github.com/tencentmusic), this mechanism facilitates the dynamic replacement of code and instructions from a remote source.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 07:10 AM
Security Audit — agent-trust-hub — qqmusic