sonoscli

Pass

Audited by Gen Agent Trust Hub on Feb 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installation metadata specifies a dependency on the 'sonos' binary, which is installed via go install github.com/steipete/sonoscli/cmd/sonos@latest from a public repository.
  • [CREDENTIALS_UNSAFE]: The skill documentation identifies the need for SPOTIFY_CLIENT_ID and SPOTIFY_CLIENT_SECRET environment variables to support optional Spotify search features. No hardcoded credentials or sensitive tokens are present within the skill's source files.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 23, 2026, 12:56 PM