spoti-cli

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated playlist purpose, including optional journal-based mood inference, but it relies on an externally installed `spoti-cli` whose publisher/source provenance was not verified. The main risk is supply-chain trust and credential forwarding to that CLI; data flow to Spotify is otherwise proportionate and uses official Spotify developer setup.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:10 AM
Package URL
pkg:socket/skills-sh/crafter-station%2Fskills%2Fspoti-cli%2F@645cabfe87a30f88f198ace25dfbe053eb8bc48b