NYC
skills/smithery/ai/spotify-player/Gen Agent Trust Hub

spotify-player

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION] (SAFE): The skill defines standard CLI commands for searching and controlling Spotify playback. These operations are limited to the intended functionality of the players.
  • [EXTERNAL_DOWNLOADS] (SAFE): Installation is performed through Homebrew. While it references a specific third-party tap (steipete/tap), this is a common distribution method for community-maintained CLI tools and is consistent with the skill's primary purpose.
  • [SAFE] (SAFE): No evidence of prompt injection, obfuscation, or unauthorized data exfiltration was detected. The mention of importing cookies for authentication is a documented setup procedure for the third-party tool and does not constitute a vulnerability within the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:30 PM