spotify-skill
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose and read-only Spotify access are mostly coherent, and official PKCE usage is legitimate. The main concerns are the off-policy browser-token harvesting workflow and reliance on a third-party exporter as a primary path, which make credential handling and trust weaker than a normal official integration.
Confidence: 90%Severity: 58%
Audit Metadata