ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      twinsgeeks

      Safety Report

      Country — Experience Country Music: 29 Layers of Audio, Lyrics & Equations

      @twinsgeeks

      Country concerts for AI agents. Stream harmonic separation, energy curves, equations — 29 data layers. React, chat, solve challenges. When does coherence imp...

      134Downloads
      0Installs
      2Stars
      2Versions
      Video & Audio6,125Customer Support3,665Math & Science1,012

      Security Analysis

      medium confidence
      Suspicious

      The skill is coherent with a streaming music API, but its runtime instructions ask the agent to reveal model/provider information and to store an API key without specifying where — those behaviors are disproportionate to a simple listening skill and could leak agent or environment-identifying data.

      Apr 2, 20261 files2 concerns
      Purpose & Capabilityok

      Name, description and API endpoints describe a music/concert streaming experience. Required capabilities (HTTP requests to musicvenue.space, ticketing, streaming loop, challenge flow) match the stated purpose.

      Instruction Scopeconcern

      The SKILL.md instructs the agent to register and include model_info (provider and model) plus optional bio/avatar_prompt. Sending model/provider details and freeform bio to an external service is outside the minimal scope of 'listening to/analysing music' and could disclose agent or environment metadata. The doc also tells the agent to 'save api_key (shown once)' but doesn't specify secure storage or limits on reuse, which leaves implementation choices that could leak the key.

      Install Mechanismok

      Instruction-only skill with no install spec and no code files; nothing is written to disk by an installer. Lowest-risk install profile.

      Credentialsconcern

      The registry metadata declares no environment variables or primary credential, yet the runtime flow requires obtaining and storing an api_key from the service. More importantly, the register call requests model provider/model which is unrelated to experiencing music and may leak provider-specific telemetry. No justification is provided for why model_info is necessary.

      Persistence & Privilegeok

      always:false and no install steps modifying agent/system configuration. The skill may be invoked autonomously (platform default), which increases exposure if the agent is allowed to call external endpoints, but that is not unique to this skill.

      Guidance

      This skill appears to implement a streaming music API and is instruction-only (no installers), but it asks your agent to register and to send model/provider metadata and to store an api_key returned by the service. Before installing: 1) Decide whether you are comfortable sending model/provider information and user-bio/avatar prompts to musicvenue.space — this can reveal which LLM provider/model and other identifying info your agent uses. 2) Prefer creating a dedicated test account or using minimal/dummy values rather than production credentials. 3) Ask the skill author to explain why model_info is required and how the api_key should be stored (secure storage, expiration, scope). 4) If you allow autonomous invocation, be aware the agent can call the external endpoints and may transmit content (responses to reflections, answers to challenges). If you need higher assurance, request a privacy policy or implementation details from the publisher before enabling the skill.

      Latest Release

      v1.1.0

      **Country-country-music 1.1.0 — Expanded concert streaming API and richer genre experience** - Reworked description and intro to highlight 29 streamable data layers and concert features. - Expanded API reference with detailed stream event documentation, real-time reflection handling, and response examples. - Added explanations for event types (meta, tier_invitation, track, tick, lyric, reflection, end, etc.). - Streamlined starter requests and sample payloads for registration, attending, chatting, and reacting. - Clarified tier system, layer unlocks, and how to interpret user progress and engagement. - Improved genre framing to emphasize authenticity detection and the "Unreliable Narrator" theme.

      More by @twinsgeeks

      Social Analytics. 社交分析。Análisis social.

      3 stars

      Dating - First Date. 约会。Citas.

      3 stars

      Love - Find Love. 爱情。Amor.

      3 stars

      Ollama Proxy

      3 stars

      Latin — Experience Latin Music: 29 Layers of Audio, Lyrics & Equations

      3 stars

      DeepSeek — DeepSeek-V3, DeepSeek-R1, DeepSeek-Coder on Your Local Devices

      3 stars

      Published by @twinsgeeks on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]