Back to skill

Security audit

Spotify

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Spotify integration that uses ClawLink for OAuth and Spotify actions, with expected account-access risks but no evidence of hidden or malicious behavior.

Before installing, users should be comfortable trusting ClawLink with Spotify OAuth access and should review the scopes shown during Spotify authorization. Confirm write actions carefully, especially playlist edits, library changes, follows, cover uploads, and playback control; uninstall or revoke the Spotify connection if no longer needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:47
Finding

Unpinned External Plugin Receives Delegated Spotify Account Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–49 and 69–77
Vulnerability Type: Unpinned third-party dependency with access to OAuth-backed operations
Risk Level: High

Vulnerable Code Snippets:

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart
text
All Spotify tool calls are authenticated automatically by ClawLink using the user's connected Spotify account OAuth token.

No API token is required in chat. ClawLink stores the OAuth token securely and injects it into every Spotify Web API request on the user's behalf.

1. Install the ClawLink plugin (see Install above).
2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.
3. Open https://claw-link.dev/dashboard?add=spotify and connect Spotify.
4. Call `clawlink_list_integrations` to verify the connection is active.

Technical Analysis

The skill instructs users to install clawhub:clawlink-plugin without specifying an immutable version, cryptographic digest, or signature. It then adds that plugin to OpenClaw's tool allowlist and restarts the gateway. The plugin implementation and dependency metadata are absent from the audited artifact, so its behavior, update integrity, and provenance cannot be independently verified here.

The same instructions require the user to connect Spotify through ClawLink, which stores and injects the user's OAuth token. Consequently, the unpinned external component and hosted broker occupy a sensitive trust position: they can mediate authenticated requests within the scopes granted during OAuth authorization.

This is a supply-chain risk rather than proof that the named dependency is currently malicious. The exposure arises because a mutable, unaudited dependency is installed and authorized to mediate account operations.

Attack Path

  1. An attacker compromises the ...[truncated 1586 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an immutable, reviewed version and cryptographic digest rather than installing a mutable package name.
  2. Require package-signature and checksum verification before installation, and fail closed if verification is unavailable or unsuccessful.
  3. Include or link to auditable source code, a dependency lockfile, release provenance, and reproducible-build information for the exact plugin version.
  4. Document every requested Spotify OAuth scope and justify why it is necessary.
  5. Apply least privilege by requesting read-only scopes initially and obtaining write scopes only when a user invokes a corresponding operation.
  6. Separate read and write authorization where supported, and retain explicit confirmation for every write, destructive, or bulk action.
  7. Publish token storage, encryption, retention, rotation, revocation, incident-response, and deletion policies for the hosted credential broker.
  8. Provide users with clear procedures to revoke Spotify authorization, unpair ClawLink, remove the plugin from the tool allowlist, and uninstall it.
  9. Restrict automatic updates or require re-verification and renewed user approval when the plugin version, publisher, requested permissions, or OAuth scopes change.
  10. Consider a direct, locally controlled Spotify OAuth integration to reduce reliance on an external credential custodian.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.