Back to skill

Security audit

Sun to Spotify

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly coherent, but it can create and upload Spotify podcast content automatically before a clear user review or confirmation step.

Review carefully before installing if you do not want an agent to create Spotify shows or upload generated episodes without a separate approval step. Prefer uv or pipx installation over the curl installer, protect Sun and Spotify credentials, and ask the agent to let you review the show title, cover, and audio before uploading.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill automates uploading generated audio, titles, descriptions, and cover art to Spotify, but it does not instruct the agent to warn the user that this sends content and metadata to a third party. That omission can lead to unintended disclosure of sensitive or proprietary material if a user provides private prompts or audio topics.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The documentation recommends `curl ... | bash`, which downloads and immediately executes a remote script without any integrity verification, pinning, or review step. If the hosting site, DNS, TLS termination, or published script is compromised, users will run attacker-controlled code on their machine.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.