spotify-player
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s capabilities broadly match Spotify terminal control, but it relies on third-party CLIs and explicitly imports browser cookies into one of them. That makes the main risk credential/session exposure to external tooling rather than clear malicious behavior or off-purpose exfiltration.
Confidence: 86%Severity: 68%
Audit Metadata