spotify-player

Warn

Audited by Socket on Jun 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent, but the preferred path relies on a third-party tap and imports browser Spotify cookies into an external CLI. No clear malicious endpoint or hidden behavior is shown, yet credential handling and install trust are broader than ideal for a media-control skill.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 26, 2026, 05:36 PM
Package URL
pkg:socket/skills-sh/CraftOS-dev%2FCraftBot%2Fspotify-player%2F@bbf5e248eda4f980998cafd3c02ef29c34bd13232343aa749926a74e9bf740ff
Security Audit — socket — spotify-player