← 返回 Skills 市场
steipete

Spotify Player

作者 Peter Steinberger · GitHub ↗ · v1.0.0
cross-platform ⚠ suspicious
28037
总下载
55
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install spotify-player
功能描述
Terminal Spotify playback/search via spogo (preferred) or spotify_player.
安全使用建议
Install only if you trust the `spogo` CLI and are comfortable letting it import Spotify authentication from your Chrome profile. Prefer an official OAuth or device-code login if available, and verify where imported tokens are stored and how to revoke or remove them.
功能分析
Type: OpenClaw Skill Name: spotify-player Version: 1.0.0 The skill bundle is classified as suspicious due to the `spogo auth import --browser chrome` command specified in `SKILL.md`. This command accesses sensitive browser cookies for authentication, which, while plausibly needed for the stated purpose of a Spotify player, represents a high-risk capability that could be abused. There is no clear evidence of intentional malicious behavior or prompt injection against the agent for data exfiltration or unauthorized actions within the provided files, but the direct access to browser data warrants a 'suspicious' classification.
能力评估
Purpose & Capability
The playback, search, device, and status commands fit the stated Spotify terminal-player purpose, and Spotify authentication is expected for that use case.
Instruction Scope
The setup step explicitly uses `spogo auth import --browser chrome`, which reaches into browser session material, but the skill does not explain what is read, where it is stored, how long it persists, or how to revoke access.
Install Mechanism
Install metadata only declares Homebrew installation of `spogo` or `spotify_player`; the sensitive authentication import is documented as a visible setup command rather than hidden automatic execution.
Credentials
Browser cookies are sensitive account/session credentials. Importing them is plausible for a Spotify CLI, but high-impact enough that the missing warning and scoping guidance warrant Review.
Persistence & Privilege
The skill likely creates persistent local authentication state for Spotify control, but provides no containment, cleanup, revocation, or safe-handling guidance.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install spotify-player
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /spotify-player 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
元数据
Slug spotify-player
版本 1.0.0
许可证
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Spotify Player 是什么?

Terminal Spotify playback/search via spogo (preferred) or spotify_player. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 28037 次。

如何安装 Spotify Player?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install spotify-player」即可一键安装,无需额外配置。

Spotify Player 是免费的吗?

是的,Spotify Player 完全免费(开源免费),可自由下载、安装和使用。

Spotify Player 支持哪些平台?

Spotify Player 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Spotify Player?

由 Peter Steinberger(@steipete)开发并维护,当前版本 v1.0.0。

💬 留言讨论