apple-music
Warn
Audited by Snyk on Feb 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The setup flow opens auth.html which, at runtime, loads and executes remote JavaScript from https://js-cdn.music.apple.com/musickit/v3/musickit.js to perform authorization and produce the Music User Token that the skill relies on, so external code is fetched and executed during runtime.
Audit Metadata