Back to skill

Security audit

Kami Smarthome Suite

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent smart-home installer, but it asks for broad install authority and handles sensitive camera/API credentials in ways users should review carefully before installing.

Install only if you are comfortable with a broad smart-home setup flow that downloads other skills and dependencies, may ask to run sudo for system packages, and stores camera/API/notification secrets in local plaintext config files. Review setup.sh and configure.py first, avoid passing API keys on the command line, rotate any key already used that way, and treat terminal output from --show or the camera wizard as sensitive because it may include camera or webhook credentials.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
setup.sh:107
Finding

Unpinned Remote Components Are Downloaded and Executed

Content
View full analysis
/dev/null || \ { print_error "Failed to clone pyenv. Please check network or install manually:" echo " git clone --depth 1 https://github.com/pyenv/pyenv.git $HOME/.pyenv" exit 2 } ``` ```bash eval "$(pyenv init --path 2>/dev/null)" || true eval "$(pyenv virtualenv-init - 2>/dev/null)" || true ``` ```bash output=$(clawhub install "$skill" 2>&1) ``` ```bash "$REQUIRED_PYTHON" -m venv .venv && \ source .venv/bin/activate && \ pip install --upgrade pip -q && \ pip install -r requirements.txt -q 2>&1 ``` ### Technical Analysis The installer retrieves pyenv from the mutable default branch without pinning a reviewed commit or verifying a signature or checksum. It also installs six ClawHub Skills without specifying immutable versions. Code generated by the downloaded pyenv installation is subsequently evaluated by the shell. The downloaded Skills' dependency manifests are then passed to `pip install`. Python package installation may execute build backends and setup hooks, so a compromised Skill manifest or dependency can execute arbitrary code during setup. The use of the official pyenv GitHub repository reduces the likelihood of malicious content compared with an unknown paste service, but it does not eliminate the risks associated with mutable remote content, upstream compromise, account takeover, DNS/TLS trust failures, or an unsafe dependency update. The six downloaded ClawHub Skills were not included in the audited artifact, so their effective payloads could not be reviewed. This behavior is relevant to the declared one-click installer functionality, but automatic execution of unpinned remote content is broader than the mini ...[truncated 1275 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
configure.py:397
Finding

Plaintext Secrets Are Duplicated into Files Without Enforced Restrictive Permissions

Content
View full analysis
None: CONFIG_FILE.write_text( json.dumps(config, indent=2, ensure_ascii=False) + "\n", encoding="utf-8" ) ok(f"Central config saved: {CONFIG_FILE}") ``` ```python def patch_json_file(path: Path, updates: Dict[str, Any]) -> bool: """Update multiple fields in a JSON config file. Special handling for `cameras` field: completely REPLACE the array from central config (Single Source of Truth), rather than merging. This prevents duplicate cameras when running --distribute multiple times. """ try: if not path.is_file(): warn(f"Skip (not found): {path}") return False original = path.read_text(encoding="utf-8") data = json.loads(original) if original.strip() else {} if not isinstance(data, dict): err(f"Top-level is not object: {path}") return False changed = False for field, value in updates.items(): if value is None or value == "": continue if field == "cameras" and isinstance(value, list): if data.get("cameras") != value: data["cameras"] = value changed = True continue if data.get(field) != value: data[field] = value changed = True if changed: path.write_text(json.dumps(data, indent=2, ensure_ascii=False) + "\n", encoding="utf-8") ok(f"{path.relative_to(SKILLS_ROOT)} updated") ``` ```python def save_credentials(api_key: str) -> None: """Cache API key to ~/.kami ...[truncated 3266 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
configure.py:738
Finding

Configuration Display Paths Reveal Camera and Notification Credentials

Content
View full analysis
" print(f" [{name}] {url}") ``` ```python url = build_rtsp_from_template(brand) if not url: continue print(f" Built URL: {url}") ``` ```python if args.show: config = load_central_config() if config: # Mask API key for display display = dict(config) key = display.get("kamiclaw_api_key", "") if key and len(key) > 12: display["kamiclaw_api_key"] = key[:8] + "..." + key[-4:] print(json.dumps(display, indent=2, ensure_ascii=False)) ``` ### Technical Analysis RTSP URLs commonly embed camera usernames and passwords in the URI authority component. The interactive wizard prints current and newly generated RTSP URLs without redaction. The `--show` operation masks only `kamiclaw_api_key`. It uses a shallow copy and emits the remainder of the configuration unchanged, including: - RTSP camera credentials - Feishu webhook secrets - Feishu application secrets - Telegram bot tokens - Discord webhook URLs - Discord bot tokens Terminal output may be retained in Agent transcripts, shell-session recordings, support logs, CI output, screen-sharing sessions, or terminal scrollback. Partial disclosure of webhook URLs can also be sensitive because webhook URLs frequently contain bearer-like secret components. ### Attack Path 1. A user configures a camera URL containing a username and password or adds notification credentials. 2. The user reruns the interactive wizard or executes `configure.sh --show`. 3. The program prints the credentials or credential-bearing URLs to standa ...[truncated 581 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
configure.sh:26
Finding

API Keys Are Exposed Through Process Arguments and Shell History

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
setup.sh:6
Finding

Installer Executes the User's Entire Shell Startup Configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (28)

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The suite design includes caching API keys and camera data in ~/.kami/credentials.json for use by multiple skills. Centralized credential storage is not inherently unsafe, but in this skill it expands the exposure surface by duplicating or propagating sensitive secrets across components, and the instructions do not specify stronger protections such as encryption, minimal retention, or access isolation beyond file mode notes elsewhere.

Content

Scanner excerpt · SKILL.md (reported line 263)May include surrounding context.

├── kami-package-detection/config.json ├── kami-conflict-detection/config.json ├── kami-suspicious-person/config.json └── ~/.kami/credentials.json + cameras.json (cached for any skill)

text

### Central config file `kami_config.json`

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · configure.py (reported line 227)May include surrounding context.

python
CONFIG_FILE = SUITE_DIR / "kami_config.json"

CRED_DIR = Path.home() / ".kami"
CRED_FILE = CRED_DIR / "credentials.json"
CAMERAS_FILE = CRED_DIR / "cameras.json"

# ---------------------------------------------------------------------------

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

save_credentials persists the API key into ~/.kami/credentials.json, creating durable local secret storage that any process running as the same user could read, and the file may also be swept into backups or sync tools. Although the code attempts chmod 0600, the secret remains plaintext on disk and the central cache increases exposure beyond transient runtime use.

Content

Scanner excerpt · configure.py (reported line 595)May include surrounding context.

python
def save_credentials(api_key: str) -> None:
    """Cache API key to ~/.kami/credentials.json."""
    try:
        CRED_DIR.mkdir(parents=True, exist_ok=True)
        data = {}

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script can execute privileged package installation via sudo apt install, which changes the host system outside the skill directory and introduces a high-impact side effect during setup. Even though it asks for confirmation, combining an ecosystem installer with optional root-level package changes increases risk, especially because earlier environment manipulation (such as sourced shell config or PATH changes) could influence what gets executed before privilege escalation is attempted.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The chained sudo apt update && sudo apt install sequence compounds risk by performing multiple privileged operations in one flow with limited opportunity for review or rollback. In an installer that already sources user shell config and automates dependency setup, such chaining makes misuse or unintended system changes harder to audit and easier to trigger once consent is given.

Content

Scanner excerpt · setup.sh (reported line 139)May include surrounding context.

sh
echo ""
        read -p "Install build dependencies with sudo? [y/N] " confirm
        if [[ "$confirm" =~ ^[Yy]$ ]]; then
            sudo apt update && sudo apt install -y \
                make build-essential libssl-dev zlib1g-dev \
                libbz2-dev libreadline-dev libsqlite3-dev \
                libncursesw5-dev xz-utils tk-dev libxml2-dev \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly directs the agent to use shell, network, file read, and file write capabilities, but it does not declare any explicit tool scope or permission boundaries. That omission makes the skill harder to sandbox and review, and increases the risk that an agent could execute installation, configuration, and credential-distribution actions with broader privileges than the user expects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Several triggers such as 'install all kami', 'smart home suite', and 'kami home assistant' are broad enough to match unrelated user requests, which can cause the wrong skill to activate. In this skill, accidental activation is more dangerous because the activated flow includes software installation, config writing, and handling of sensitive camera and API credentials.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

The installation flow explicitly contemplates paths that may request sudo to install Python build dependencies. Invoking privilege-requiring setup from a skill materially raises the risk of system-wide modification, especially because it is part of an automated installer bundle that also downloads additional components from the network.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
`setup.sh` performs:
1. One-shot install of all 6 Kami ecosystem skills from ClawHub
2. Detect / install Python 3.10:
   - **Debian/Ubuntu**: prefer conda → pyenv → system python3.10 (avoids `python3.10-venv` sudo dependency)
   - **Other systems**: prefer system python3.10 → pyenv → conda
   - If none found: auto-install (conda preferred → pyenv as fallback), no sudo required; only pyenv source build will ask for sudo when build-deps are missing
3. Interactive prompts for centralized config (API key, camera URL, notifications)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

This section again indicates that setup may escalate to sudo when dependencies are missing, reinforcing that the skill can lead an agent into privileged execution paths. In context, that is risky because the same setup process also installs interpreters, dependencies, and multiple sub-skills, expanding the blast radius of any mistake or compromise.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
2. Detect / install Python 3.10:
   - **Debian/Ubuntu**: prefer conda → pyenv → system python3.10 (avoids `python3.10-venv` sudo dependency)
   - **Other systems**: prefer system python3.10 → pyenv → conda
   - If none found: auto-install (conda preferred → pyenv as fallback), no sudo required; only pyenv source build will ask for sudo when build-deps are missing
3. Interactive prompts for centralized config (API key, camera URL, notifications)
4. Auto-distribute the centralized config to each skill's local config files

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to run setup.sh and configure.sh --distribute based on state checks, without requiring a fresh execution-time confirmation from the user. Those scripts install software, create environments, write configuration files, and propagate credentials to multiple sub-skills, so accidental or premature execution could make broad system and privacy-impacting changes.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

bash
  bash {baseDir}/setup.sh

This script will: download all 6 sub-skills from ClawHub + create venvs + install dependencies

  • If present: skip and proceed to config check

Step 1: Configure KamiClaw API key

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The interactive setup collects API keys, webhook URLs, bot tokens, and app secrets and then saves them into a local JSON file in plaintext via save_central_config, but the user is not clearly warned that these secrets will be stored on disk. In a smart-home bundle this is meaningful because the same central file aggregates multiple sensitive credentials, increasing the blast radius if the host is shared, backed up insecurely, or later exfiltrated by another process.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · configure.py (reported line 460)May include surrounding context.

python
The suite treats the dict key as the canonical camera identifier (the user-
    facing "name"). To keep alarm messages and logs human-readable, we ALWAYS
    overwrite any inner `device_id` field with the dict key, so the value users
    see in notifications matches what they typed in `kami_config.json`.
    """
    if not isinstance(c, dict):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The template workflow prints the fully rendered RTSP URL back to the console, and those URLs commonly embed camera usernames and passwords. This exposes credentials to terminal history, logs, screen recording, shoulder surfing, or agent transcript capture, which is especially sensitive in a home-security context because it can grant access to camera feeds.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · configure.sh (reported line 22)May include surrounding context.

sh
fi

if ! command -v python3 &> /dev/null; then
    echo "[x] python3 not found. Install: sudo apt install -y python3" >&2
    exit 2
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 98)May include surrounding context.

sh
fi

if ! command -v python3 &> /dev/null; then
    echo "[x] python3 not found. Install: sudo apt install -y python3" >&2
    exit 2
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 100)May include surrounding context.

sh
fi

if ! command -v python3 &> /dev/null; then
    echo "[x] python3 not found. Install: sudo apt install -y python3" >&2
    exit 2
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 106)May include surrounding context.

sh
fi

if ! command -v python3 &> /dev/null; then
    echo "[x] python3 not found. Install: sudo apt install -y python3" >&2
    exit 2
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 127)May include surrounding context.

sh
fi

if ! command -v python3 &> /dev/null; then
    echo "[x] python3 not found. Install: sudo apt install -y python3" >&2
    exit 2
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 135)May include surrounding context.

sh
fi

if ! command -v python3 &> /dev/null; then
    echo "[x] python3 not found. Install: sudo apt install -y python3" >&2
    exit 2
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 184)May include surrounding context.

sh
fi

if ! command -v python3 &> /dev/null; then
    echo "[x] python3 not found. Install: sudo apt install -y python3" >&2
    exit 2
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 260)May include surrounding context.

sh
fi

if ! command -v python3 &> /dev/null; then
    echo "[x] python3 not found. Install: sudo apt install -y python3" >&2
    exit 2
fi

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The camera identifiers and related config values use Chinese-specific naming ('yuanqu', 'bangongshi') without any indication that the skill supports user language choice or that the locale is intentionally region-scoped. This can violate language/locale policy when a skill implicitly assumes one locale rather than offering opt-in or documenting the constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installer sources the user's entire ~/.bashrc before performing setup actions, which executes arbitrary shell code from a user-controlled startup file in the installer's trust context. This expands the attack surface significantly: aliases, functions, PATH changes, command wrappers, traps, or arbitrary commands in .bashrc can alter or hijack later operations such as clawhub, git, conda, pip, sudo prompts, or Python setup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatic privileged package installation is only revealed after pyenv build failure, not clearly disclosed up front before the setup begins. This is dangerous because users may start a seemingly local skill installer without realizing it can later request and perform root-level system modifications as part of error recovery.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.