controlling-spotify

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/apply-patch.js

This module is primarily a self-modifying build/installation patcher that rewrites src/utils.ts by inserting credential-handling logic into loadSpotifyConfig(). It does not show direct malware behaviors like network access or command execution, but it creates a meaningful supply-chain risk due to runtime code alteration and it wires sensitive secrets (SPOTIFY_CLIENT_SECRET and SPOTIFY_REFRESH_TOKEN) into application logic. Additionally, on failure it may disclose local source content via a preview in logs. Overall: suspicious/needs review in a supply-chain context, but direct malicious payload indicators are limited in this snippet.

Confidence: 75%Severity: 60%
Audit Metadata
Analyzed At
May 3, 2026, 01:16 PM
Package URL
pkg:socket/skills-sh/oaustegard%2Fclaude-skills%2Fcontrolling-spotify%2F@74ba611631e4de5d80970c2c23c9f493f1e91160