mcp-applemusic Security Audit Report
mcp-applemusic is an AI agent skill, created by epheterson and published at epheterson/mcp-applemusic. ClawSecure audited mcp-applemusic across 67 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 124 findings concentrate in Data Exfiltration, Supply Chain Attack and Command Injection, including Credential Harvesting via Network and Multi-File Data Exfiltration Chain. 12 were rated high or critical severity.
Is mcp-applemusic safe?
ClawSecure audited mcp-applemusic and assigned a security score of 0/100 (High Risk), identifying 124 findings across Data Exfiltration and Supply Chain Attack. Review the findings below before installing.
What did ClawSecure find in mcp-applemusic?
ClawSecure identified 124 findings in mcp-applemusic, concentrated in Data Exfiltration, Supply Chain Attack and Command Injection. 12 were rated high or critical severity. The most severe include Credential Harvesting via Network and Multi-File Data Exfiltration Chain.
How was mcp-applemusic audited?
ClawSecure ran mcp-applemusic through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 67 files from epheterson/mcp-applemusic.
What does a score of 0 mean?
ClawSecure assigned mcp-applemusic a security score of 0/100, placing it in the High Risk range. This is driven by 124 findings led by Data Exfiltration that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for mcp-applemusic
ClawSecure detected 124 security findings in mcp-applemusic, spanning Data Exfiltration, Supply Chain Attack, Command Injection and Hardcoded Secrets.
- critical · Credential Harvesting via Network. Data Exfiltration finding.
- critical · Multi-File Data Exfiltration Chain. Data Exfiltration finding.
- critical · Environment Variable Exfiltration via Network. Data Exfiltration finding detected in
src/applemusic_mcp/auth.py. - critical · Dangerous combination of code execution and system commandsβ¦. Command Injection finding detected in
src/applemusic_mcp/browser.py. - critical · Environment Variable Exfiltration via Network. Data Exfiltration finding detected in
src/applemusic_mcp/server.py. - high · Suspicious Pattern: open(key_path. Data Exfiltration finding detected in
src/applemusic_mcp/auth.py:377. - high · Suspicious Pattern: eyJ****. Hardcoded Secrets finding detected in
tests/conftest.py:282. - high · Suspicious Pattern: eyJ****. Hardcoded Secrets finding detected in
tests/test_auth_cov.py:237. - high · Suspicious Pattern: eyJ****. Hardcoded Secrets finding detected in
tests/test_harvest.py:25. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
CHANGELOG.md. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
cli.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
safari_player.py.
Showing the 12 highest-severity of 124 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for mcp-applemusic
Audit external network connections
Harden command execution
Eliminate dynamic code execution
Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI AgentsβBeyond Static Scans: Why ClawSecure Verifies Agentic IntentβRelated AI Agent Security Audits
Scanned on August 6, 2026. mcp-applemusic is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.