spotify-player

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it relies on third-party Spotify CLIs and a cookie-import auth flow that routes sensitive session data into external software rather than an official Spotify auth path. This is a medium-high security risk with limited evidence of outright malware.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:40 PM
Package URL
pkg:socket/skills-sh/LETTA-AI%2FSKILLS%2Fspotify-player%2F@8b452ef6549918eb9a3041c4eeb226d63b2ba338