spotify-player
Pass
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of terminal commands specifically for the 'spogo' and 'spotify_player' utilities. These commands are used for legitimate playback controls, such as playing, pausing, and searching for music.
- [EXTERNAL_DOWNLOADS]: The skill references the installation of CLI tools through a Homebrew tap (steipete/tap). This is a standard and transparent method for distributing niche developer tools on macOS and Linux systems.
- [SAFE]: The analysis found no evidence of prompt injection, data exfiltration, or persistence mechanisms. The mention of importing authentication cookies for 'spogo' is a documented local setup step for that specific tool and does not involve transmitting sensitive data to untrusted destinations.
Audit Metadata