Spotify

Security checks across malware telemetry and agentic risk

Overview

This Spotify skill is a disclosed connector wrapper that can read and change a user's Spotify account, with no evidence of hidden or unrelated behavior.

Install only if you are comfortable connecting Spotify through OOMOL and allowing the agent to perform Spotify actions on your behalf. Confirm exact targets before saves, follows, unfollows, playlist edits, removals, or playback changes, and review OOMOL/Spotify permissions during connection.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Confidence
91% confidence
Finding
This action saves episodes to the authenticated user's Spotify library, which is a state-changing operation on user data. The documentation does not clearly warn that invoking it will modify the user's account, increasing the risk of unintended changes if an agent uses it without explicit user awareness or confirmation.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This action performs a destructive account change by unfollowing artists or users, but the skill text provides no warning that it alters the authenticated user's Spotify state. In an agent setting, missing explicit user-warning language increases the chance of silent or unintended account modifications, especially if an upstream planner invokes the skill from a loosely phrased request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal