Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add martin-gomola/spotify-mcp --skill use-spotifygit clone --depth 1 https://github.com/martin-gomola/spotify-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/martin-gomola/spotify-mcp/use-spotify)<a href="https://agentmods.dev/skills/martin-gomola/spotify-mcp/use-spotify"><img src="https://agentmods.dev/badge/skills/martin-gomola/spotify-mcp/use-spotify/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/martin-gomola/spotify-mcp/use-spotify"><img src="https://agentmods.dev/badge/skills/martin-gomola/spotify-mcp/use-spotify.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00088 | $0.00335 |
| Opus 5 | $0.00044 | $0.00168 |
| Sonnet 5 | $0.00018 | $0.00067 |
| Haiku 4.5 | $0.00009 | $0.00034 |
Grade A, and why
use-spotify scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Use Spotify
Choose one route from the user's intent. Do not list or inventory the full Spotify MCP tool catalog. Read only the matching route file, then call only the tools named there.
- Exact track, artist, releases, search, or library save/remove/check: routes/catalog-library.md
- Current playback, devices, queue, or playback control: routes/playback.md
- Podcasts, shows, or episodes: routes/podcasts.md
- Existing playlist lookup or contents: routes/playlists.md
If a request crosses routes, read only those routes. Preserve exact Spotify URIs, inspect uncertain
write results, and, when MCP Apps are supported, call spotify_render_results exactly once after
the final playable results are verified and before the textual completion response. Every rendered
item must include its concrete kind; use kind: playlist for playlist cards. A plain Markdown
link is not a substitute when the renderer is available. If rendering itself fails, report it and
fall back to canonical Spotify links without retrying the renderer.
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 24 lines · 88 tokens per session scan A 6b13201b341e
use-spotify is a skill published in the GitHub repository martin-gomola/spotify-mcp (0 stars, last pushed yesterday), licensed MIT. It adds 88 tokens to every session and 335 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
post-to-xhs
A publishing guide for 小红书, a Chinese social-media platform. It covers posting image-and-text content or a longer formatted article, using supplied content or a webpage.
screenshot-camera
Capture a screenshot from a Unity Camera and return it as a PNG image for direct LLM inspection. Falls back to Camera.main (then any active camera) when cameraRef is null. Width and height are capped to keep response size manageable.
screenshot-game-view
Capture a screenshot of the Unity Editor's Game View by reading its internal render texture directly. Image size matches the current Game View resolution; the tool corrects Y-flip on DirectX / Metal so the output is always upright. Requires an open Game View window.
screenshot-scene-view
Capture a screenshot from the Unity Editor Scene View at the requested size. Renders via the Scene View's active camera onto a temporary RenderTexture. Requires an open Scene View.
AI Image & Video Generator — GPT Image 2, Seedance, ComfyUI
Generate images and videos from text with multi-provider routing — supports GPT Image 2.0 (near-perfect text rendering), Nanobanana 2, Seedream 5.0, Midjourney V8.1 (unified photorealistic + anime), Flux 2 Klein (cheap drafts), Seedance 2.0 / Veo 3.1 / Grok Video / Agnes Video, and local ComfyUI workflows. Includes…
image-prompting
Use when generating or editing images via blockrunimage — especially with GPT Image 2, Nano Banana, or Grok Imagine for posters, UI mockups, marketing assets, product shots, or anything with on-image text. Turns vague user requests ("make me a cool poster") into structured, text-accurate prompts that actually render…