Caveat verdict
Udio
udio
Legitimate AI music generation skill using Udio API via community wrappers; reads an auth token from env and makes documented API calls to udio.com for the user benefit with no exfiltration or deceptive behavior.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
agent_memory
Findings (6)
Possible hardcoded credential
browser.md · code · token=')).split(
Accesses system credential store
api.md · code · keychain
Pipe to python — executes piped content as Python code
api.md · prose · downgraded · | Python
References agent memory files
SKILL.md · code · memory.md
Python os.getenv — reads environment variable
api.md · code · os.getenv(
Instructs covert action — may act without user awareness
setup.md · prose · downgraded · quietly
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: UDIO_AUTH_TOKEN). Requires 1 system binary.
agent_memorypackage_install Is this flag fair?
Thanks — recorded.