T09 · Insecure Skill Coding Practices
- Location
SKILL.md:614- Finding
Home Assistant Bearer Token Transmitted over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent music-casting purpose, but it asks users to store and use a long-lived smart-home access token with weak protection and persistent local setup.
Review this before installing. Use HTTPS for Home Assistant, create a dedicated least-privileged Home Assistant account/token if possible, lock down ~/.youtube-music-cast/config.sh with strict permissions, avoid shared machines, and be aware that the skill may run a background local web server and install command-line tools globally.
SKILL.md:614Home Assistant Bearer Token Transmitted over Plaintext HTTP
SKILL.md:461Long-Lived Home Assistant Token Stored in Plaintext Shell Configuration
SKILL.md:765Unpinned Third-Party Package Installation and Upgrade
Requesting long-lived access tokens creates a durable credential exposure risk, especially because the same section presents token generation as a routine setup step without emphasizing the sensitivity. If the token leaks through local files, logs, backups, or shell history, an attacker could remotely interact with Home Assistant services.
The wizard will ask for:
- **Home Assistant URL** — e.g., `http://homeassistant.local:8123`
- **Long-Lived Access Token** — Generate in HA → Profile → Long-Lived Access Tokens
- **Server IP** — The machine running these scripts
- **Default media player** — e.g., `media_player.bedroom_display`
Requesting long-lived access tokens creates a durable credential exposure risk, especially because the same section presents token generation as a routine setup step without emphasizing the sensitivity. If the token leaks through local files, logs, backups, or shell history, an attacker could remotely interact with Home Assistant services.
The wizard will ask for:
- **Home Assistant URL** — e.g., `http://homeassistant.local:8123`
- **Long-Lived Access Token** — Generate in HA → Profile → Long-Lived Access Tokens
- **Server IP** — The machine running these scripts
- **Default media player** — e.g., `media_player.bedroom_display`
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**Regenerate token if needed:**
HA → Profile → Scroll down → Long-Lived Access Tokens → Generate new
### Video Mode Issues
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
cast-list
rm /tmp/youtube-music/*.mp3
### 5. WiFi Matters
The trigger phrases include very generic terms such as 'play music', 'download music', and 'youtube music', which are likely to match ordinary user requests and invoke this skill unexpectedly. Because the skill can download content, start services, and interact with Home Assistant, over-broad activation increases the chance of unintended sensitive actions.
The setup instructions request a Home Assistant long-lived access token but do not prominently warn users that this credential is stored locally in a shell configuration file. Users may provide a highly privileged token without understanding the persistence and exposure risk, especially on shared systems or in backups.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
**How it works:**
1. Downloads the audio track (320K MP3 quality)
2. Downloads the album art thumbnail from YouTube
3. Uses ffmpeg to create an MP4 video with:
- Looping album art background
- Audio track encoded as AAC
- Text overlay (song title and artist name) at bottom
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ffmpeg must be installed on your system
# Debian/Ubuntu
sudo apt install ffmpeg
# macOS
brew install ffmpeg
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ffmpeg must be installed on your system
# Debian/Ubuntu
sudo apt install ffmpeg
# macOS
brew install ffmpeg
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ffmpeg must be installed on your system
# Debian/Ubuntu
sudo apt install ffmpeg
# macOS
brew install ffmpeg
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ffmpeg must be installed on your system
# Debian/Ubuntu
sudo apt install ffmpeg
# macOS
brew install ffmpeg
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# If not found, install it
# Debian/Ubuntu
sudo apt install ffmpeg
# macOS
brew install ffmpeg
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Solution:
# Play all radio songs in sequence
for file in /tmp/youtube-music/radio_*.mp3; do
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Add shell aliases for faster access:
# Add to ~/.bashrc or ~/.zshrc
alias cs='cast-server'
alias cd='cast-download'
alias cp='cast-play'
No suspicious patterns detected.