spotify-skill

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose and read-only Spotify access are mostly coherent, and official PKCE usage is legitimate. The main concerns are the off-policy browser-token harvesting workflow and reliance on a third-party exporter as a primary path, which make credential handling and trust weaker than a normal official integration.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Sep 3, 2026, 05:11 PM
Package URL
pkg:socket/skills-sh/idanbeck%2Fclaude-skills%2Fspotify-skill%2F@a548571bea01e0c128e1a3e0cbc2b9c22f35d8d55f0c8db20212f96143987ea5
Security Audit — socket — spotify-skill