Security audit
Spotify Player
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed Spotify CLI helper that stores Spotify cookies locally so a headless Linux server can control playback.
Install only if you are comfortable giving the agent Spotify playback control and storing Spotify session cookies on this machine. Keep ~/.config/spogo and the cookie file permission-restricted, do not paste or log the cookie values elsewhere, remove the cookies when no longer needed, and consider pinning or reviewing the upstream spogo version before installing.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
66/66 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
