T05 · Unauthorized Access and Privilege Escalation
- Location
SETUP.md:49- Finding
Spotify OAuth Flow Requests Permissions Beyond the Skill's Functional Requirements
- Content
View full analysis
Vulnerability Details
File Location:
SETUP.md:49-51
Vulnerability Type: Excessive OAuth scopes and violation of least privilege
Risk Level: MediumVulnerable Code Snippet:
bash # Scopes needed for full playback + library control SCOPES="playlist-read-private playlist-read-collaborative streaming user-modify-playback-state user-library-read user-library-modify playlist-modify-private playlist-modify-public user-read-playback-state user-read-currently-playing user-read-recently-played user-top-read"Technical Analysis
The setup process asks users to authorize Spotify scopes that are not required by the implemented functionality. The reviewed scripts use playback control, playback and device state, currently playing information, recently played history, and Spotify search.
No reviewed code modifies the user's saved library or playlists, reads private or collaborative playlists, accesses top-item data, or implements the Spotify Web Playback SDK. Consequently, the following requested scopes exceed the Skill's demonstrated requirements:
playlist-read-privateplaylist-read-collaborativestreaminguser-library-readuser-library-modifyplaylist-modify-privateplaylist-modify-publicuser-top-read
OAuth access and refresh tokens inherit these unnecessary privileges. This expands the consequences of token disclosure or misuse even though no direct credential exfiltration was found in the reviewed code.
Attack Path
- The user follows
SETUP.mdand authorizes the complete scope list. - Spotify issues a refresh token carrying both necessary playback permissions and unnecessary library, playlist, and account-data permissions.
- The refresh token is stored in
projects/spotify/tokens.json. - A malicious local process, compromised agent Skill, or other actor with access to that token obtains it.
- The actor exchanges the refresh token for an acce ...[truncated 990 chars]
- Remediation
View remediation
Remediation Suggestions
Apply least privilege to the Spotify authorization flow:
- Reduce the documented scope list to the scopes used by the current implementation:
user-modify-playback-stateuser-read-playback-stateuser-read-currently-playinguser-read-recently-played
- Remove playlist, library, top-items, and streaming scopes unless corresponding functionality is implemented and clearly disclosed.
- Explain why each requested scope is necessary beside the authorization command.
- Instruct existing users to revoke the current Spotify application authorization and reauthorize it with the reduced scope set. Merely changing the documentation will not reduce privileges already attached to existing refresh tokens.
- Consider separating optional features into separate consent flows so that additional scopes are requested only when the user explicitly enables those features.
- Reduce the documented scope list to the scopes used by the current implementation:
