T08 ยท Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Third-Party Package Installation and Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Home Assistant skill does what it claims, but it gives an agent real smart-home control while under-disclosing token, transport, and package-execution risks.
Review this skill before installing. Use HTTPS or a trusted encrypted tunnel for Home Assistant, provide a dedicated revocable token with the least permissions available, avoid controlling safety-sensitive devices through broad agent prompts, and prefer a pinned or otherwise verified mcporter installation instead of the unpinned npx fallback.
SKILL.md:13Unpinned Third-Party Package Installation and Execution
SKILL.md:64Home Assistant Bearer Token Can Be Transmitted over Plaintext HTTP
The usage section documents commands that can remotely control smart-home devices but provides no warning about safety-critical effects, such as unlocking, powering devices, or changing states that may affect occupants or property. In a home-automation context, omitted safety guidance increases the chance of dangerous or unintended real-world actions through normal use or prompt-driven misuse.
The configuration instructions tell users to transmit a bearer token in an HTTP header for remote control but do not warn that this is a long-lived secret granting control over Home Assistant. If mishandled through shell history, logs, screenshots, misconfigured URLs, or insecure transport, the token could be reused to query states or control devices.
The skill recommends falling back to npx -y mcporter, which fetches and executes a package at runtime without pinning an exact version. This creates a supply-chain risk: a compromised upstream package, typo-squatted dependency, or unexpected breaking release could lead to arbitrary code execution in the user's environment.
No suspicious patterns detected.