Skip to main content

kosmi-dj

Transforms an AI agent into a video DJ for Kosmi watch parties, automating video playback and room management.

Install this skill

or
0/100

Security score

The kosmi-dj skill was audited on Feb 16, 2026 and we found 10 security issues across 3 threat categories, including 6 high-severity. Review the findings below before installing.

Categories Tested

Security Issues

high line 13

Template literal with variable interpolation in command context

SourceSKILL.md
13- A `.env` file at `${CLAUDE_PLUGIN_ROOT}/.env` containing room URL and credentials
high line 18

Template literal with variable interpolation in command context

SourceSKILL.md
18Load from `${CLAUDE_PLUGIN_ROOT}/.env` before any agent-browser calls:
high line 33

Template literal with variable interpolation in command context

SourceSKILL.md
33Execute `${CLAUDE_PLUGIN_ROOT}/skills/kosmi-dj/scripts/kosmi-connect.sh` to:
high line 44

Template literal with variable interpolation in command context

SourceSKILL.md
44Execute `${CLAUDE_PLUGIN_ROOT}/skills/kosmi-dj/scripts/kosmi-play.sh <VIDEO_URL>` to:
high line 55

Template literal with variable interpolation in command context

SourceSKILL.md
55Execute `${CLAUDE_PLUGIN_ROOT}/skills/kosmi-dj/scripts/kosmi-loop.sh` to:
high line 97

Template literal with variable interpolation in command context

SourceSKILL.md
97Run `${CLAUDE_PLUGIN_ROOT}/skills/kosmi-dj/scripts/kosmi-snapshot-debug.sh` to dump a human-readable snapshot of all interactive elements currently visible. Use this to discover exact button names and
medium line 13

Access to .env file

SourceSKILL.md
13- A `.env` file at `${CLAUDE_PLUGIN_ROOT}/.env` containing room URL and credentials
medium line 18

Access to .env file

SourceSKILL.md
18Load from `${CLAUDE_PLUGIN_ROOT}/.env` before any agent-browser calls:
medium line 104

Access to .env file

SourceSKILL.md
104- If login fails, check credentials in `.env` or delete the session to force re-auth:
low line 22

External URL reference

SourceSKILL.md
22| `KOSMI_ROOM_URL` | Yes | Full URL to the Kosmi room (e.g. `https://app.kosmi.io/room/XXXXX`) |
Scanned on Feb 16, 2026
View Security Dashboard
Installation guide →
GitHub Stars 2.2K
Rate this skill
Categorymarketing
UpdatedApril 10, 2026
openclaw/skills