It appears in the read me that you are recommending the developer of an application to distribute their private key for the last.FM integration to all customers of their app.
And I am now reading through the last FM documentation and this seems correct.
Also, this sounds like a security disaster.
Whether it is correct or not, please specify in the readme what is happening at a high-level.