spotify-player
Warn
Audited by Socket on Aug 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The overall purpose is coherent, and the fallback `spotify_player` path is relatively normal, but the preferred `spogo` path increases risk because it is installed from a personal Homebrew tap and imports browser cookies for authentication. I found no clear evidence of malicious exfiltration or proxy interception, so this is not malware, but it poses medium security risk due to third-party credential handling and supply-chain trust concerns.
Confidence: 82%Severity: 62%
Audit Metadata