T07 · Tool Hijacking and Spoofing
- Location
spotify_api_lookup.py:18- Finding
External Authentication Module Loaded Through Python Path Manipulation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a plausible Spotify artist-research tool, but it uses under-disclosed external authentication code and account-level Spotify credentials that are broader than needed for public artist reporting.
Install only if you are comfortable reviewing or replacing the external spotify-songs-to-notion authentication helper first. Prefer a version that uses a skill-local, read-only Spotify client credentials flow, reads only the required Spotify variables, and clearly forbids playlist, library, playback, and other account-mutating actions for artist research.
spotify_api_lookup.py:18External Authentication Module Loaded Through Python Path Manipulation
spotify_api_lookup.py:23Credentials Loaded from an Undocumented External Project Environment File
spotify_api_lookup.py:26User OAuth Authentication Exceeds the Privileges Required for Public Artist Research
The skill is presented as an artist research/reporting workflow, yet it documents availability of mutating Spotify endpoints such as PUT/DELETE /me/library and 'Full player control endpoints'. Including account-modifying capabilities unrelated to the skill's stated purpose increases the chance that an agent could invoke destructive or privacy-impacting actions on a user's Spotify account beyond simple research.
- GET /me — Current user profile
- GET /me/playlists — User's playlists
- POST /me/playlists — Create playlist
- PUT/DELETE /me/library — Save/remove items
- Full player control endpoints
### ❌ Removed/Restricted Endpoints
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `PUT /me/audiobooks` | Save audiobooks | `PUT /me/library` |
| `PUT /me/following` | Follow artists | `PUT /me/library` |
| `PUT /playlists/{id}/followers` | Follow playlist | `PUT /me/library` |
| `DELETE /me/tracks` | Remove tracks | `DELETE /me/library` |
| `DELETE /me/albums` | Remove albums | `DELETE /me/library` |
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `PUT /me/audiobooks` | Save audiobooks | `PUT /me/library` |
| `PUT /me/following` | Follow artists | `PUT /me/library` |
| `PUT /playlists/{id}/followers` | Follow playlist | `PUT /me/library` |
| `DELETE /me/tracks` | Remove tracks | `DELETE /me/library` |
| `DELETE /me/albums` | Remove albums | `DELETE /me/library` |
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `PUT /me/audiobooks` | Save audiobooks | `PUT /me/library` |
| `PUT /me/following` | Follow artists | `PUT /me/library` |
| `PUT /playlists/{id}/followers` | Follow playlist | `PUT /me/library` |
| `DELETE /me/tracks` | Remove tracks | `DELETE /me/library` |
| `DELETE /me/albums` | Remove albums | `DELETE /me/library` |
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `PUT /me/audiobooks` | Save audiobooks | `PUT /me/library` |
| `PUT /me/following` | Follow artists | `PUT /me/library` |
| `PUT /playlists/{id}/followers` | Follow playlist | `PUT /me/library` |
| `DELETE /me/tracks` | Remove tracks | `DELETE /me/library` |
| `DELETE /me/albums` | Remove albums | `DELETE /me/library` |
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `PUT /me/audiobooks` | Save audiobooks | `PUT /me/library` |
| `PUT /me/following` | Follow artists | `PUT /me/library` |
| `PUT /playlists/{id}/followers` | Follow playlist | `PUT /me/library` |
| `DELETE /me/tracks` | Remove tracks | `DELETE /me/library` |
| `DELETE /me/albums` | Remove albums | `DELETE /me/library` |
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `PUT /me/audiobooks` | Save audiobooks | `PUT /me/library` |
| `PUT /me/following` | Follow artists | `PUT /me/library` |
| `PUT /playlists/{id}/followers` | Follow playlist | `PUT /me/library` |
| `DELETE /me/tracks` | Remove tracks | `DELETE /me/library` |
| `DELETE /me/albums` | Remove albums | `DELETE /me/library` |
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `PUT /me/audiobooks` | Save audiobooks | `PUT /me/library` |
| `PUT /me/following` | Follow artists | `PUT /me/library` |
| `PUT /playlists/{id}/followers` | Follow playlist | `PUT /me/library` |
| `DELETE /me/tracks` | Remove tracks | `DELETE /me/library` |
| `DELETE /me/albums` | Remove albums | `DELETE /me/library` |
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `PUT /me/audiobooks` | Save audiobooks | `PUT /me/library` |
| `PUT /me/following` | Follow artists | `PUT /me/library` |
| `PUT /playlists/{id}/followers` | Follow playlist | `PUT /me/library` |
| `DELETE /me/tracks` | Remove tracks | `DELETE /me/library` |
| `DELETE /me/albums` | Remove albums | `DELETE /me/library` |
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `PUT /me/audiobooks` | Save audiobooks | `PUT /me/library` |
| `PUT /me/following` | Follow artists | `PUT /me/library` |
| `PUT /playlists/{id}/followers` | Follow playlist | `PUT /me/library` |
| `DELETE /me/tracks` | Remove tracks | `DELETE /me/library` |
| `DELETE /me/albums` | Remove albums | `DELETE /me/library` |
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `PUT /me/following` | Follow artists | `PUT /me/library` |
| `PUT /playlists/{id}/followers` | Follow playlist | `PUT /me/library` |
| `DELETE /me/tracks` | Remove tracks | `DELETE /me/library` |
| `DELETE /me/albums` | Remove albums | `DELETE /me/library` |
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
| `DELETE /me/audiobooks` | Remove audiobooks | `DELETE /me/library` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `PUT /playlists/{id}/followers` | Follow playlist | `PUT /me/library` |
| `DELETE /me/tracks` | Remove tracks | `DELETE /me/library` |
| `DELETE /me/albums` | Remove albums | `DELETE /me/library` |
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
| `DELETE /me/audiobooks` | Remove audiobooks | `DELETE /me/library` |
| `DELETE /me/following` | Unfollow artists | `DELETE /me/library` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `DELETE /me/tracks` | Remove tracks | `DELETE /me/library` |
| `DELETE /me/albums` | Remove albums | `DELETE /me/library` |
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
| `DELETE /me/audiobooks` | Remove audiobooks | `DELETE /me/library` |
| `DELETE /me/following` | Unfollow artists | `DELETE /me/library` |
| `DELETE /playlists/{id}/followers` | Unfollow playlist | `DELETE /me/library` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `DELETE /me/albums` | Remove albums | `DELETE /me/library` |
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
| `DELETE /me/audiobooks` | Remove audiobooks | `DELETE /me/library` |
| `DELETE /me/following` | Unfollow artists | `DELETE /me/library` |
| `DELETE /playlists/{id}/followers` | Unfollow playlist | `DELETE /me/library` |
| `POST /playlists/{id}/tracks` | Add items to playlist | `POST /playlists/{id}/items` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `DELETE /me/episodes` | Remove episodes | `DELETE /me/library` |
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
| `DELETE /me/audiobooks` | Remove audiobooks | `DELETE /me/library` |
| `DELETE /me/following` | Unfollow artists | `DELETE /me/library` |
| `DELETE /playlists/{id}/followers` | Unfollow playlist | `DELETE /me/library` |
| `POST /playlists/{id}/tracks` | Add items to playlist | `POST /playlists/{id}/items` |
| `GET /playlists/{id}/tracks` | Get playlist items | `GET /playlists/{id}/items` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `DELETE /me/shows` | Remove shows | `DELETE /me/library` |
| `DELETE /me/audiobooks` | Remove audiobooks | `DELETE /me/library` |
| `DELETE /me/following` | Unfollow artists | `DELETE /me/library` |
| `DELETE /playlists/{id}/followers` | Unfollow playlist | `DELETE /me/library` |
| `POST /playlists/{id}/tracks` | Add items to playlist | `POST /playlists/{id}/items` |
| `GET /playlists/{id}/tracks` | Get playlist items | `GET /playlists/{id}/items` |
| `DELETE /playlists/{id}/tracks` | Remove playlist items | `DELETE /playlists/{id}/items` |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `DELETE /playlists/{id}/followers` | Unfollow playlist | `DELETE /me/library` |
| `POST /playlists/{id}/tracks` | Add items to playlist | `POST /playlists/{id}/items` |
| `GET /playlists/{id}/tracks` | Get playlist items | `GET /playlists/{id}/items` |
| `DELETE /playlists/{id}/tracks` | Remove playlist items | `DELETE /playlists/{id}/items` |
| `PUT /playlists/{playlist_id}/tracks` | Update playlist items | `PUT /playlists/{id}/items` |
## ✅ AVAILABLE Endpoints
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `DELETE /playlists/{id}/followers` | Unfollow playlist | `DELETE /me/library` |
| `POST /playlists/{id}/tracks` | Add items to playlist | `POST /playlists/{id}/items` |
| `GET /playlists/{id}/tracks` | Get playlist items | `GET /playlists/{id}/items` |
| `DELETE /playlists/{id}/tracks` | Remove playlist items | `DELETE /playlists/{id}/items` |
| `PUT /playlists/{playlist_id}/tracks` | Update playlist items | `PUT /playlists/{id}/items` |
## ✅ AVAILABLE Endpoints
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| `DELETE /playlists/{id}/followers` | Unfollow playlist | `DELETE /me/library` |
| `POST /playlists/{id}/tracks` | Add items to playlist | `POST /playlists/{id}/items` |
| `GET /playlists/{id}/tracks` | Get playlist items | `GET /playlists/{id}/items` |
| `DELETE /playlists/{id}/tracks` | Remove playlist items | `DELETE /playlists/{id}/items` |
| `PUT /playlists/{playlist_id}/tracks` | Update playlist items | `PUT /playlists/{id}/items` |
## ✅ AVAILABLE Endpoints
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
import spotipy
from dotenv import load_dotenv
load_dotenv(os.path.dirname(os.path.abspath(__file__)) + "/../../spotify-songs-to-notion/.env")
def get_client():
The prerequisites require Spotify API credentials in .env but provide no guidance on secret handling, least privilege, or preventing disclosure in generated outputs, logs, or error messages. In an agent setting, referencing credentials without guardrails increases the risk of accidental exposure or misuse of authentication material.
The file states that Polish characters in output should be handled by replacing emojis and using 'ASCII-safe output,' which imposes a constrained language/encoding style rather than offering the user a choice. There is no opt-in, alternative locale handling, or justification that would exempt this behavior under the policy.
The module docstring says the output contains "Artist metadata, discography, related artists (no followers/popularity)", which communicates that popularity data is not included. However, the formatter later prints each searched track's popularity, so the documentation actively contradicts actual output behavior rather than merely omitting an implementation detail.
The skill explicitly instructs saving generated reports to reports/artist-report-{name}-{date}.md but does not warn that user-supplied artist queries and synthesized analysis will be persisted to disk. This can create unintended local data retention, especially if reports include sensitive business assessments, internal notes, or fetched third-party data the user expected only in-chat.
No suspicious patterns detected.