Spotify Player

Security checks across malware telemetry and agentic risk

Overview

This Spotify skill is purpose-aligned, but its setup asks users to import authentication from a Chrome browser profile without explaining the credential risk or storage boundaries.

Install only if you trust the spogo CLI and are comfortable letting it import Spotify authentication from Chrome. Prefer an official OAuth or device-code login if available, and verify where spogo stores imported tokens and how to revoke them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs users to import Spotify authentication cookies directly from a browser profile, which involves handling active session tokens. Even if intended for legitimate login convenience, this exposes highly sensitive session data without any warning about token sensitivity, scope, storage, or the risk of credential/session compromise if the tool or environment is untrusted.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal