T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned External Plugin Receives Delegated Spotify Account Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–49 and 69–77
Vulnerability Type: Unpinned third-party dependency with access to OAuth-backed operations
Risk Level: HighVulnerable Code Snippets:
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restarttext All Spotify tool calls are authenticated automatically by ClawLink using the user's connected Spotify account OAuth token. No API token is required in chat. ClawLink stores the OAuth token securely and injects it into every Spotify Web API request on the user's behalf. 1. Install the ClawLink plugin (see Install above). 2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet. 3. Open https://claw-link.dev/dashboard?add=spotify and connect Spotify. 4. Call `clawlink_list_integrations` to verify the connection is active.Technical Analysis
The skill instructs users to install
clawhub:clawlink-pluginwithout specifying an immutable version, cryptographic digest, or signature. It then adds that plugin to OpenClaw's tool allowlist and restarts the gateway. The plugin implementation and dependency metadata are absent from the audited artifact, so its behavior, update integrity, and provenance cannot be independently verified here.The same instructions require the user to connect Spotify through ClawLink, which stores and injects the user's OAuth token. Consequently, the unpinned external component and hosted broker occupy a sensitive trust position: they can mediate authenticated requests within the scopes granted during OAuth authorization.
This is a supply-chain risk rather than proof that the named dependency is currently malicious. The exposure arises because a mutable, unaudited dependency is installed and authorized to mediate account operations.
Attack Path
- An attacker compromises the ...[truncated 1586 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an immutable, reviewed version and cryptographic digest rather than installing a mutable package name.
- Require package-signature and checksum verification before installation, and fail closed if verification is unavailable or unsuccessful.
- Include or link to auditable source code, a dependency lockfile, release provenance, and reproducible-build information for the exact plugin version.
- Document every requested Spotify OAuth scope and justify why it is necessary.
- Apply least privilege by requesting read-only scopes initially and obtaining write scopes only when a user invokes a corresponding operation.
- Separate read and write authorization where supported, and retain explicit confirmation for every write, destructive, or bulk action.
- Publish token storage, encryption, retention, rotation, revocation, incident-response, and deletion policies for the hosted credential broker.
- Provide users with clear procedures to revoke Spotify authorization, unpair ClawLink, remove the plugin from the tool allowlist, and uninstall it.
- Restrict automatic updates or require re-verification and renewed user approval when the plugin version, publisher, requested permissions, or OAuth scopes change.
- Consider a direct, locally controlled Spotify OAuth integration to reduce reliance on an external credential custodian.
