Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The usage text exposes a setup flow for capturing and persisting highly sensitive Spotify session cookies (sp_dc and sp_key), but the skill metadata does not disclose this credential-handling behavior. In an agent context, hidden credential collection and local persistence materially changes the trust model because users may invoke a benign-looking playback skill without realizing it stores reusable authentication tokens.
