connector-spotify
MANDATORY recipe for every Caffeine build.
What this skill does for you
MANDATORY recipe for every Caffeine build that reads Spotify catalog data or drives a user's Spotify account from a canister. The supported path is the `spotify-client` mops package (Spotify Web API) over outbound HTTPS with an OAuth 2.0 bearer token minted off-chain. Hand-rolling `ic.http_request` calls to `api.spotify.com` is a FORBIDDEN anti-pattern : it bypasses the non-replicated-outcall safeguard (player state and `progress_ms` differ per node and fail consensus), the generated JSON decoding, and the bearer handling. Load this skill whenever the user, spec, or any prior task mentions Spotify, a song, track, artist, album, playlist, music search, new releases, genres, markets, "what's playing", recently played, the queue, player controls (play / pause / skip / shuffle / repeat), a saved library, podcasts (shows or episodes), chapters or audiobooks : and BEFORE writing any code that touches a Spotify endpoint.
Quoted from the skill description in the pinned sourceWho made it
Use it with Edge
Set up Edge for me: read getedge.cc/SKILL.md and follow it. Then use Edge to load the connector-spotify skill from caffeinelabs/skills.
Paste it into Claude, ChatGPT, Codex or Cursor.
Or read the skill source first.
Security evidence
| Scanner | Date | Result | Findings |
|---|---|---|---|
| Edge static checks | 2026-09-27 | Pass | 0 |
| Cisco skill-scanner | 2026-09-27 | Pass | 0 |
| Semgrep Edge rules | 2026-09-27 | Pass | 0 |
Static scans check the code, not how well the skill works.
Scanner scope, raw findings and mirrored provider records
Edge static checks (Edge-run): edge-static/1.0.1. Scope: Static patterns for remote execution, credentials with network sends, obfuscation, prompt overrides, hidden Unicode, binaries and persistence. Revision: e5cacdfe5ce55e939edb02980fca800c0c13f421. Raw findings: . Counted findings: .
Cisco skill-scanner (Edge-run): cisco-skill-scanner/2.1.0. Scope: Local static, YARA, pipeline and behavioral analyzers; no LLM or AI Defense analysis. Revision: e5cacdfe5ce55e939edb02980fca800c0c13f421. Raw findings: 1. Counted findings: .
Semgrep Edge rules (Edge-run): semgrep/1.178.0+edge-rules.c15016a36fd3+offline-v1. Scope: Six Edge-authored static rules with Semgrep CE; offline execution and metrics disabled. Semgrep-maintained rules excluded. Revision: e5cacdfe5ce55e939edb02980fca800c0c13f421. Raw findings: . Counted findings: .
Source and licence
- Repository
- https://github.com/caffeinelabs/skills
- Pinned skill file
- View source at revision
- Revision
- e5cacdfe5ce55e939edb02980fca800c0c13f421
- Package hash
- sha256:e614b91b1995e7ab886627ee977eba734079f15933ea048c49e30f9906159686
- Licence
- Apache-2.0