Edge Copy setup link
Skill evidence / connector-spotify
Skill profile

connector-spotify

MANDATORY recipe for every Caffeine build.

What this skill does for you

MANDATORY recipe for every Caffeine build that reads Spotify catalog data or drives a user's Spotify account from a canister. The supported path is the `spotify-client` mops package (Spotify Web API) over outbound HTTPS with an OAuth 2.0 bearer token minted off-chain. Hand-rolling `ic.http_request` calls to `api.spotify.com` is a FORBIDDEN anti-pattern : it bypasses the non-replicated-outcall safeguard (player state and `progress_ms` differ per node and fail consensus), the generated JSON decoding, and the bearer handling. Load this skill whenever the user, spec, or any prior task mentions Spotify, a song, track, artist, album, playlist, music search, new releases, genres, markets, "what's playing", recently played, the queue, player controls (play / pause / skip / shuffle / repeat), a saved library, podcasts (shows or episodes), chapters or audiobooks : and BEFORE writing any code that touches a Spotify endpoint.

Quoted from the skill description in the pinned source

Who made it

Publishercaffeinelabs
Repositoryskills
Installs1,100as of Sep 27, 2026

Use it with Edge

Set up Edge for me: read getedge.cc/SKILL.md and follow it. Then use Edge to load the connector-spotify skill from caffeinelabs/skills.

Paste it into Claude, ChatGPT, Codex or Cursor.

Or read the skill source first.

Security evidence

Security state at 2026-09-30: reviewed. State definitions. This records static evidence for this revision; live load eligibility is checked again.

3 static scans, 0 counted findings. The listed scanners recorded the results shown for this package revision.

ScannerDateResultFindings
Edge static checks2026-09-27Pass0
Cisco skill-scanner2026-09-27Pass0
Semgrep Edge rules2026-09-27Pass0

Static scans check the code, not how well the skill works.

Scanner scope, raw findings and mirrored provider records

Edge static checks (Edge-run): edge-static/1.0.1. Scope: Static patterns for remote execution, credentials with network sends, obfuscation, prompt overrides, hidden Unicode, binaries and persistence. Revision: e5cacdfe5ce55e939edb02980fca800c0c13f421. Raw findings: . Counted findings: .

Cisco skill-scanner (Edge-run): cisco-skill-scanner/2.1.0. Scope: Local static, YARA, pipeline and behavioral analyzers; no LLM or AI Defense analysis. Revision: e5cacdfe5ce55e939edb02980fca800c0c13f421. Raw findings: 1. Counted findings: .

Semgrep Edge rules (Edge-run): semgrep/1.178.0+edge-rules.c15016a36fd3+offline-v1. Scope: Six Edge-authored static rules with Semgrep CE; offline execution and metrics disabled. Semgrep-maintained rules excluded. Revision: e5cacdfe5ce55e939edb02980fca800c0c13f421. Raw findings: . Counted findings: .

Source and licence

Repository
https://github.com/caffeinelabs/skills
Pinned skill file
View source at revision
Revision
e5cacdfe5ce55e939edb02980fca800c0c13f421
Package hash
sha256:e614b91b1995e7ab886627ee977eba734079f15933ea048c49e30f9906159686
Licence
Apache-2.0