configure

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Executes local Python scripts included in the skill package (scripts/oauth-flow.py and scripts/refresh-token.py) to manage the OAuth 2.0 authorization flow and token lifecycle.
  • [COMMAND_EXECUTION]: Uses the macOS security utility to manage sensitive credentials. It stores the client_secret in the system keychain and retrieves it for token exchanges, ensuring the secret is never written to plaintext configuration files.
  • [EXTERNAL_DOWNLOADS]: Connects to accounts.spotify.com and api-partner.spotify.com to perform the OAuth flow and verify the resulting configuration. These network operations target official Spotify services necessary for the skill's functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 07:29 PM
Security Audit — agent-trust-hub — configure