Back to skill

Security audit

๐Ÿ  Home Assistant via MCP protocol

Security checks for vulnerabilities and agentic risk

Overview

This Home Assistant skill does what it claims, but it gives an agent real smart-home control while under-disclosing token, transport, and package-execution risks.

Review this skill before installing. Use HTTPS or a trusted encrypted tunnel for Home Assistant, provide a dedicated revocable token with the least permissions available, avoid controlling safety-sensitive devices through broad agent prompts, and prefer a pinned or otherwise verified mcporter installation instead of the unpinned npx fallback.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 ยท Insecure Dependencies

Error
Location
SKILL.md:13
Finding

Unpinned Third-Party Package Installation and Execution

Content
View full analysis
Remediation
View remediation

T09 ยท Insecure Skill Coding Practices

Error
Location
SKILL.md:64
Finding

Home Assistant Bearer Token Can Be Transmitted over Plaintext HTTP

Content
View full analysis
` over the unencrypted connection. 3. An attacker on the same wireless network, compromised network infrastructure, or another position capable of observing or manipulating traffic captures the request. 4. The attacker extracts the bearer token from the authorization header. 5. The attacker submits authenticated requests to the reachable Home Assistant MCP endpoint using the stolen token. 6. Home Assistant accepts operations within the permissions associated with that token until ...[truncated 535 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The usage section documents commands that can remotely control smart-home devices but provides no warning about safety-critical effects, such as unlocking, powering devices, or changing states that may affect occupants or property. In a home-automation context, omitted safety guidance increases the chance of dangerous or unintended real-world actions through normal use or prompt-driven misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The configuration instructions tell users to transmit a bearer token in an HTTP header for remote control but do not warn that this is a long-lived secret granting control over Home Assistant. If mishandled through shell history, logs, screenshots, misconfigured URLs, or insecure transport, the token could be reused to query states or control devices.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill recommends falling back to npx -y mcporter, which fetches and executes a package at runtime without pinning an exact version. This creates a supply-chain risk: a compromised upstream package, typo-squatted dependency, or unexpected breaking release could lead to arbitrary code execution in the user's environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.