spotify-player

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The overall purpose is coherent, and the fallback `spotify_player` path is relatively normal, but the preferred `spogo` path increases risk because it is installed from a personal Homebrew tap and imports browser cookies for authentication. I found no clear evidence of malicious exfiltration or proxy interception, so this is not malware, but it poses medium security risk due to third-party credential handling and supply-chain trust concerns.

Confidence: 82%Severity: 62%
Audit Metadata
Analyzed At
Aug 1, 2026, 08:33 AM
Package URL
pkg:socket/skills-sh/LinkupPlatform%2Fopenclaw%2Fspotify-player%2F@67b94199f75be9026dbbfd4e944f6a2c9b42603c14fb4d2fdfc6ff027cdda2f8
Security Audit — socket — spotify-player