spotify-player

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configuration automates the installation of the spogo CLI tool from a third-party repository (steipete/tap) and the spotify_player tool using the Homebrew package manager.
  • [COMMAND_EXECUTION]: The skill's primary functionality is achieved by executing shell commands for external binaries, specifically spogo and spotify_player.
  • [PROMPT_INJECTION]: The skill processes untrusted data from the Spotify API (track and artist names) which creates a surface for indirect prompt injection (Ingestion points: CLI search output; Boundary markers: absent; Capability inventory: shell command execution; Sanitization: absent).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 08:32 AM
Security Audit — agent-trust-hub — spotify-player