skills/steipete/openclaw/sonoscli/Gen Agent Trust Hub

sonoscli

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the sonos command-line utility from the author's GitHub repository (github.com/steipete/sonoscli) using the Go package manager. This is a standard installation method for the specified tool.
  • [COMMAND_EXECUTION]: The skill executes the sonos binary to perform local network operations such as device discovery, status retrieval, and playback control. All commands are consistent with the skill's stated purpose of managing Sonos speakers.
  • [DATA_EXPOSURE]: The skill mentions optional usage of SPOTIFY_CLIENT_ID and SPOTIFY_CLIENT_SECRET for Spotify integration but does not include instructions to hardcode, log, or exfiltrate these credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 02:10 PM
Security Audit — agent-trust-hub — sonoscli