Back to skill

Security audit

Spotify Playlist Curator

Security checks for vulnerabilities and agentic risk

Overview

This Spotify playlist skill is coherent and purpose-aligned, but users should know it stores Spotify tokens and taste preferences locally and calls third-party music services.

Install only if you are comfortable granting Spotify scopes that can read listening history and private playlists, create or modify playlists, and control playback queueing. Keep the skill directory private, do not share or commit .env, spotify_tokens.json, or taste_profile.json, and consider tightening file permissions or pinning dependencies before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Create Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-2; installed by scripts/setup.sh:25-26
Vulnerability Type: Unconstrained dependency installation
Risk Level: Medium

Vulnerable Code

requirements.txt:1-2:

text
spotipy
requests

scripts/setup.sh:25-26:

bash
python -m pip install --upgrade pip
python -m pip install -r "$SKILL_DIR/requirements.txt"

Technical Analysis

The Skill installs spotipy and requests without version constraints or package hashes. Consequently, every setup can resolve to a different dependency version from the configured Python package index.

This prevents reproducible installation and means a future compromised, malicious, or incompatible dependency release could be installed automatically without any corresponding change to the reviewed Skill package. The setup script also upgrades pip without pinning it, further changing the installation environment outside the audited artifact.

No evidence indicates that the currently named packages are typosquatted or malicious. The vulnerability is the absence of controls ensuring that future installations use reviewed dependency artifacts.

Attack Path

  1. An attacker compromises the release process or publishing account of a dependency, or compromises the package source configured for pip.
  2. The attacker publishes a malicious version that satisfies the unconstrained requirement.
  3. A user runs bash scripts/setup.sh.
  4. Pip resolves and installs the malicious release.
  5. Malicious package code executes during installation or when the Spotify scripts import the dependency.
  6. The payload runs with the privileges of the user who invoked setup or the Skill.

Impact Assessment

A compromised dependency could execute arbitrary code with the invoking user's local privileges. Potential consequences include reading Spotify client credentials and OAuth tokens, modifying local files, acce ...[truncated 280 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to an explicitly reviewed version, for example:
    text
    spotipy==REVIEWED_VERSION
    requests==REVIEWED_VERSION
    
  2. Generate a lock file containing all transitive dependencies.
  3. Require cryptographic hashes during installation, such as with a hash-locked requirements file and pip install --require-hashes.
  4. Pin the installer version instead of unconditionally upgrading pip to the latest release.
  5. Use a trusted or controlled package index and explicitly configure the allowed index.
  6. Add automated dependency vulnerability and integrity scanning to the release process.
  7. Review and regenerate pins on a controlled schedule rather than accepting new releases automatically during user setup.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/spotify_auth.py:13
Finding

Spotify Credentials and OAuth Tokens Are Written Without Enforced Restrictive Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/spotify_auth.py:13-23; repeated during token refresh at scripts/spotify_client.py:184-193; credential file created at scripts/setup.sh:35-43
Vulnerability Type: Insecure local storage of sensitive authentication material
Risk Level: Medium

Vulnerable Code

scripts/spotify_auth.py:13-23:

python
def save_tokens(token_info: dict, out_path: Path) -> Path:
    data = {
        "access_token": token_info.get("access_token"),
        "refresh_token": token_info.get("refresh_token"),
        "scope": token_info.get("scope"),
        "expires_at": token_info.get("expires_at"),
        "token_type": token_info.get("token_type"),
    }
    out_path.parent.mkdir(parents=True, exist_ok=True)
    out_path.write_text(json.dumps(data, indent=2))
    return out_path

scripts/spotify_client.py:184-193:

python
def _save_tokens(self, token_info: dict[str, Any]) -> None:
    data = {
        "access_token": token_info.get("access_token"),
        "refresh_token": getattr(self._oauth, "refresh_token", None),
        "scope": token_info.get("scope", ""),
        "expires_at": token_info.get("expires_at", 0),
        "token_type": token_info.get("token_type", "Bearer"),
    }
    self._tokens_path.parent.mkdir(parents=True, exist_ok=True)
    self._tokens_path.write_text(json.dumps(data, indent=2))

scripts/setup.sh:35-43:

bash
if [ ! -f "$ENV_FILE" ]; then
  cat > "$ENV_FILE" <<'EOF'
# Spotify API credentials
# Get these from https://developer.spotify.com/dashboard
# When creating your app, set the redirect URI to: http://127.0.0.1:8888/callback
SPOTIPY_CLIENT_ID=your_client_id_here
SPOTIPY_CLIENT_SECRET=your_client_secret_here
EOF

Technical Analysis

The .env credential file and Spotify token JSON files are created using ordinary shell redirection or Path.write_text(). Neither implementati ...[truncated 2046 chars]

Remediation
View remediation

Remediation Suggestions

  1. Set umask 077 near the beginning of scripts/setup.sh before creating .env or other secret-bearing files.
  2. Create token files atomically with owner-only permissions:
    • Open a temporary file with mode 0600.
    • Write and flush the JSON.
    • Atomically replace the destination.
  3. Explicitly apply chmod(0o600) after creating or replacing .env and token files.
  4. Validate existing sensitive files before reading or rewriting them. Warn or fail if group or other permission bits are set.
  5. Ensure parent secret directories are owner-only, preferably mode 0700.
  6. Avoid placing token files in broadly shared working directories. Prefer a user-specific configuration directory with restrictive permissions.
  7. Document that token files contain reusable authentication material and must not be committed, shared, logged, or included in backups without encryption.
  8. Consider using an operating-system credential store instead of plaintext JSON where supported.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (55)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Persistent storage of user preferences across sessions in a local file is a materially different behavior from transient Spotify playlist operations, especially when not clearly disclosed in the metadata/description. This creates privacy and retention risk because sensitive preference data may be stored unexpectedly, reused by later sessions, or exposed through local file access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Persistent storage of user preferences across sessions in a local file is a materially different behavior from transient Spotify playlist operations, especially when not clearly disclosed in the metadata/description. This creates privacy and retention risk because sensitive preference data may be stored unexpectedly, reused by later sessions, or exposed through local file access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Persistent storage of user preferences across sessions in a local file is a materially different behavior from transient Spotify playlist operations, especially when not clearly disclosed in the metadata/description. This creates privacy and retention risk because sensitive preference data may be stored unexpectedly, reused by later sessions, or exposed through local file access.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
.venv/bin/python scripts/spotify_cli.py --json status

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

md
.venv/bin/python scripts/spotify_cli.py --json status

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 363)May include surrounding context.

md
.venv/bin/python scripts/spotify_cli.py --json status

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 385)May include surrounding context.

md
.venv/bin/python scripts/spotify_cli.py --json status

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 386)May include surrounding context.

md
.venv/bin/python scripts/spotify_cli.py --json status

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 391)May include surrounding context.

md
.venv/bin/python scripts/spotify_cli.py --json status

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup.md (reported line 29)May include surrounding context.

md
This avoids relying on shell activation state and is usually safer to copy and paste.

The auth helper opens a browser for Spotify OAuth consent and writes a token file containing the refresh token and access token metadata.

## Required environment

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/spotify_auth.py (reported line 91)May include surrounding context.

python
This avoids relying on shell activation state and is usually safer to copy and paste.

The auth helper opens a browser for Spotify OAuth consent and writes a token file containing the refresh token and access token metadata.

## Required environment

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 30)May include surrounding context.

sh
python -m pip install --upgrade pip
python -m pip install -r "$SKILL_DIR/requirements.txt"

ENV_FILE="$SKILL_DIR/.env"

echo
echo "Setup complete. Dependencies installed."

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 49)May include surrounding context.

sh
python -m pip install --upgrade pip
python -m pip install -r "$SKILL_DIR/requirements.txt"

ENV_FILE="$SKILL_DIR/.env"

echo
echo "Setup complete. Dependencies installed."

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/spotify_client.py (reported line 39)May include surrounding context.

python
python -m pip install --upgrade pip
python -m pip install -r "$SKILL_DIR/requirements.txt"

ENV_FILE="$SKILL_DIR/.env"

echo
echo "Setup complete. Dependencies installed."

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/spotify_client.py (reported line 40)May include surrounding context.

python
python -m pip install --upgrade pip
python -m pip install -r "$SKILL_DIR/requirements.txt"

ENV_FILE="$SKILL_DIR/.env"

echo
echo "Setup complete. Dependencies installed."

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/spotify_client.py (reported line 41)May include surrounding context.

python
python -m pip install --upgrade pip
python -m pip install -r "$SKILL_DIR/requirements.txt"

ENV_FILE="$SKILL_DIR/.env"

echo
echo "Setup complete. Dependencies installed."

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 44)May include surrounding context.

sh
SPOTIPY_CLIENT_ID=your_client_id_here
SPOTIPY_CLIENT_SECRET=your_client_secret_here
EOF
  echo "Created .env at $ENV_FILE"
  echo ""
  echo "Next steps:"
  echo "  1. Go to https://developer.spotify.com/dashboard and create an app"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 58)May include surrounding context.

sh
SPOTIPY_CLIENT_ID=your_client_id_here
SPOTIPY_CLIENT_SECRET=your_client_secret_here
EOF
  echo "Created .env at $ENV_FILE"
  echo ""
  echo "Next steps:"
  echo "  1. Go to https://developer.spotify.com/dashboard and create an app"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/spotify_auth.py (reported line 78)May include surrounding context.

python
SPOTIPY_CLIENT_ID=your_client_id_here
SPOTIPY_CLIENT_SECRET=your_client_secret_here
EOF
  echo "Created .env at $ENV_FILE"
  echo ""
  echo "Next steps:"
  echo "  1. Go to https://developer.spotify.com/dashboard and create an app"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/spotify_auth.py (reported line 81)May include surrounding context.

python
SPOTIPY_CLIENT_ID=your_client_id_here
SPOTIPY_CLIENT_SECRET=your_client_secret_here
EOF
  echo "Created .env at $ENV_FILE"
  echo ""
  echo "Next steps:"
  echo "  1. Go to https://developer.spotify.com/dashboard and create an app"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/spotify_cli.py (reported line 45)May include surrounding context.

python
SPOTIPY_CLIENT_ID=your_client_id_here
SPOTIPY_CLIENT_SECRET=your_client_secret_here
EOF
  echo "Created .env at $ENV_FILE"
  echo ""
  echo "Next steps:"
  echo "  1. Go to https://developer.spotify.com/dashboard and create an app"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/spotify_client.py (reported line 71)May include surrounding context.

python
SPOTIPY_CLIENT_ID=your_client_id_here
SPOTIPY_CLIENT_SECRET=your_client_secret_here
EOF
  echo "Created .env at $ENV_FILE"
  echo ""
  echo "Next steps:"
  echo "  1. Go to https://developer.spotify.com/dashboard and create an app"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/spotify_client.py (reported line 80)May include surrounding context.

python
SPOTIPY_CLIENT_ID=your_client_id_here
SPOTIPY_CLIENT_SECRET=your_client_secret_here
EOF
  echo "Created .env at $ENV_FILE"
  echo ""
  echo "Next steps:"
  echo "  1. Go to https://developer.spotify.com/dashboard and create an app"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/spotify_client.py (reported line 84)May include surrounding context.

python
SPOTIPY_CLIENT_ID=your_client_id_here
SPOTIPY_CLIENT_SECRET=your_client_secret_here
EOF
  echo "Created .env at $ENV_FILE"
  echo ""
  echo "Next steps:"
  echo "  1. Go to https://developer.spotify.com/dashboard and create an app"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/spotify_client.py (reported line 88)May include surrounding context.

python
SPOTIPY_CLIENT_ID=your_client_id_here
SPOTIPY_CLIENT_SECRET=your_client_secret_here
EOF
  echo "Created .env at $ENV_FILE"
  echo ""
  echo "Next steps:"
  echo "  1. Go to https://developer.spotify.com/dashboard and create an app"

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/spotify_auth.py:28

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/spotify_client.py:161