spotify-player

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill contains no malicious code, hidden instructions, or unauthorized data access patterns.
  • [EXTERNAL_DOWNLOADS]: Provides instructions to install spogo and spotify_player via Homebrew. These tools are reputable open-source projects for terminal media control.
  • [PROMPT_INJECTION]: The skill includes functionality to process user-provided search queries. 1. Ingestion points: User strings for track searches in SKILL.md. 2. Boundary markers: Examples use double quotes to delimit query parameters. 3. Capability inventory: Execution of search and playback commands via Spotify CLI tools. 4. Sanitization: Relies on the underlying CLI utilities for input handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 01:00 PM