spotify-player

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, but it prefers a third-party CLI from a personal Homebrew tap and instructs importing browser cookies, which is sensitive credential access. No clear evidence of exfiltration to non-Spotify endpoints was found, so this is not confirmed malware, but the install and auth model create meaningful security risk.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
May 19, 2026, 03:12 AM
Package URL
pkg:socket/skills-sh/steipete%2Fclawdis%2Fspotify-player%2F@f7723b096950492779bd9b7d988de5e105f67acb
Security Audit — socket — spotify-player