Back to skill

Security audit

Spotify Player

Security checks for vulnerabilities and agentic risk

Overview

This Spotify CLI skill is mostly coherent, but it asks users to import Chrome Spotify cookies through an unpinned third-party tool without clearly warning or scoping that credential access.

Review this skill before installing. Only run the Chrome cookie import if you trust the installed spogo binary and understand that browser cookies can act like account credentials. Prefer a safer OAuth or device-login flow where available, and verify the tool source before granting it browser profile access.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:16
Finding

Unrestricted Browser Cookie Import Exposes Sensitive Authentication Material

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 16
Vulnerability Type: Browser credential access without documented scope restrictions
Risk Level: Medium

Complete Code Snippet:

markdown
spogo setup
- Import cookies: `spogo auth import --browser chrome`

Technical Analysis

The skill instructs the agent to execute a third-party program that imports authentication cookies directly from Chrome. Browser cookie stores contain sensitive session material, and access to them crosses a significant security boundary.

The instruction does not specify a Chrome profile, limit extraction to Spotify domains, identify which cookies are accessed, or require the user to review and explicitly approve the operation immediately before execution. Although cookie import may be an intended authentication mechanism for spogo, the unrestricted instruction delegates access to sensitive browser data without documenting least-privilege controls.

The project contains no executable implementation of spogo, so the audit cannot establish that the program actually extracts unrelated cookies or exfiltrates credentials. The identified risk is the excessive trust granted to an external binary and the absence of safeguards around credential-store access.

Attack Path

  1. An agent loads the skill and determines that Spotify authentication is required.
  2. Following SKILL.md, the agent executes spogo auth import --browser chrome.
  3. The installed spogo binary is granted or obtains access to Chrome's cookie storage.
  4. If that binary or its distribution channel has been compromised, it can attempt to read authentication material available through that access.
  5. Exposed session material could then be retained or transmitted by the compromised binary and potentially used to impersonate affected browser sessions.

This attack path requires a malicious or compromised external executable; the reviewed file does not i ...[truncated 647 chars]

Remediation
View remediation

Remediation Suggestions

  • Prefer Spotify's documented OAuth authorization flow with the minimum required scopes instead of importing browser cookies.
  • Require explicit, contemporaneous user confirmation before accessing browser credential storage.
  • Document the exact cookie domains and data fields the client needs.
  • Restrict import to Spotify-owned domains and a user-selected Chrome profile.
  • Explain where imported credentials are stored, how they are protected, and how users can revoke or delete them.
  • Avoid logging cookie values, authorization headers, or derived tokens.
  • Verify the installed client before permitting credential access, using a trusted release source, immutable version, and integrity verification.
  • If domain-restricted import cannot be guaranteed, remove the automated cookie-import instruction and direct users to a safer authorization workflow.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Preferred Spotify Client Is Installed from an Unpinned Third-Party Homebrew Tap

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Mutable and unpinned third-party dependency
Risk Level: Medium

Complete Code Snippet:

markdown
metadata: {"clawdbot":{"emoji":"🎵","requires":{"anyBins":["spogo","spotify_player"]},"install":[{"id":"brew","kind":"brew","formula":"spogo","tap":"steipete/tap","bins":["spogo"],"label":"Install spogo (brew)"},{"id":"brew","kind":"brew","formula":"spotify_player","bins":["spotify_player"],"label":"Install spotify_player (brew)"}]}}

Technical Analysis

The skill designates spogo as its preferred Spotify client and defines installation through the third-party Homebrew tap steipete/tap. The metadata does not pin the formula to an immutable version or repository commit and does not provide an expected artifact checksum or signature.

As a result, the software installed when the skill is used may differ from the software that existed when the skill was audited. If the tap repository, formula, release account, or referenced artifact is compromised, an attacker could substitute executable content while preserving the expected spogo command name.

No evidence in the reviewed project demonstrates that the current tap or package is malicious. The vulnerability is the mutable trust relationship and lack of integrity controls, which is particularly significant because the same skill subsequently instructs the installed program to access browser cookies.

Attack Path

  1. An attacker compromises the third-party Homebrew tap, its maintainer account, or an artifact location referenced by its formula.
  2. The attacker modifies the formula or release artifact while retaining the expected package and executable names.
  3. A user or agent follows the skill installation metadata and installs spogo from the mutable tap.
  4. Homebrew resolves and installs the attacker-controlled version because the skill specifies no immutable revision or ind ...[truncated 1086 chars]
Remediation
View remediation

Remediation Suggestions

  • Prefer an official, independently reviewed distribution channel where available.
  • Pin the dependency to an immutable release version and repository commit.
  • Record and verify cryptographic checksums or signatures for downloaded artifacts.
  • Configure automated monitoring for unexpected formula, ownership, signing-key, and artifact changes.
  • Review the Homebrew formula and its transitive download sources before installation.
  • Separate dependency installation from credential import and require explicit user approval before each security-sensitive operation.
  • Document the trusted publisher, repository, expected package identifier, version, checksum, and verification procedure in the skill.
  • Re-audit the dependency whenever the pinned version is updated.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs users to import Spotify authentication cookies from a browser profile without any warning about the sensitivity of those cookies or the trust boundary involved. Browser cookies can grant account access, so normalizing cookie extraction in a generic skill increases the risk of credential misuse, accidental disclosure, or use of a third-party tool in a way that users may not recognize as sensitive.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.