Back to plugin

Security audit

OpenClaw Spotify

Security checks for vulnerabilities and agentic risk

Overview

This Spotify plugin is purpose-aligned and disclosed, though it does require Spotify account credentials and can change playlists or playback when used.

Install only if you are comfortable granting OpenClaw access to your Spotify account for playlist edits, cover uploads, and playback control. Keep playlist approval settings on prompt for destructive changes unless you intentionally want automation, and remember that hiding a playlist from your profile does not make its link private.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
openclaw.plugin.json:26
Evidence
"description": "Spotify OAuth redirect URI for generating and exchanging PKCE authorization codes. Falls back to SPOTIFY_REDIRECT_URI, then http://127.0.0.1:437...