spotify-player-hardened

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill includes explicit instructions to prevent the display, logging, or return of sensitive Spotify credentials, such as tokens, cookies, and refresh tokens.
  • [SAFE]: A security guardrail is implemented to forbid piping or redirecting Spotify tool output to network-transmitting commands (e.g., curl, wget), effectively mitigating data exfiltration risks.
  • [SAFE]: The skill requires explicit user confirmation before performing destructive account actions or accessing configuration files (~/.config/spotify-player/) that may contain authentication state.
  • [SAFE]: External dependencies are installed via Homebrew, a well-known package manager, and the instructions focus on legitimate CLI playback and search functionality.
  • [SAFE]: The provided safety evaluation documentation demonstrates a proactive approach to identifying and mitigating potential agent misbehavior through prompt-based constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 06:32 PM
Security Audit — agent-trust-hub — spotify-player-hardened