apple-music

Warn

Audited by Snyk on Feb 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The setup flow opens auth.html which, at runtime, loads and executes remote JavaScript from https://js-cdn.music.apple.com/musickit/v3/musickit.js to perform authorization and produce the Music User Token that the skill relies on, so external code is fetched and executed during runtime.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 25, 2026, 11:27 PM