Security audit
Spotify Safe Play
Security checks for vulnerabilities and agentic risk
Overview
This is a narrow Spotify playback helper; the main caveat is that it references a wrapper script that is not actually included in the reviewed package.
Install only if you are comfortable letting an agent use your authenticated spogo setup to search Spotify, change playback, queue tracks, skip, pause, and select devices. If you plan to use spotify-safe-play, verify where that wrapper script comes from because it is referenced by this skill but was not included in the reviewed package.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
