Back to skill

Security audit

Aqara OpenAPI Local

Security checks for vulnerabilities and agentic risk

Overview

This Aqara smart-home skill is purpose-aligned, but it needs Review because it can control or delete live home resources while sending bearer tokens to any configured endpoint and storing sensitive local data without explicit restrictive permissions.

Install only if you trust the configured Aqara endpoint and understand that the CLI can control physical devices, change rooms, and create/update/enable/disable/delete automations. Prefer environment variables or a tightly permissioned config file, verify the endpoint is the real Aqara API URL before use, and require explicit confirmation before executing device-control, batch, or delete operations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
lib/http.js:12
Finding

Bearer Token Can Be Transmitted to an Arbitrary Configured Endpoint

Content
View full analysis
({ ...currentConfig, endpointUrl: normalizedEndpointUrl, })); outputPayload({ success: true, configPath, endpointUrl: normalizedEndpointUrl, }, options, (payload) => { printKeyValues(payload); }); } ``` ### Technical Analysis Authenticated network communication is necessary for the declared Aqara API functionality. However, the implementation treats `AQARA_ENDPOINT_URL` and the value accepted by `aqara config set-endpoint` as trusted without validating their protocol, hostname, port, or relationship to an approved Aqara API domain. Every network-backed operation then attaches the configured bearer token to this endpoint. Consequently, anyone able to influence t ...[truncated 2166 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
lib/config.js:105
Finding

Bearer Token and Smart-Home Device Data Are Persisted Without Explicit Restrictive Permissions

Content
View full analysis
({ ...currentConfig, token: normalizedToken, })); outputPayload({ success: true, configPath, tokenMasked: maskToken(normalizedToken), }, options, (payload) => { printKeyValues(payload); }); } ``` `lib/cache.js:128-145`: ```js try { fs.writeFileSync( tempCachePath, `${JSON.stringify(responseData, null, 2)}\n`, 'utf8', ); if (fs.existsSync(runtimeConfig.cachePath)) { fs.unlinkSync(runtimeConfig.cachePath); } fs.renameSync(tempCachePath, runtimeConfig.cachePath); } catch (error) { if (fs.existsSync(tempCachePath)) { fs.unlinkSync(tempCachePath); } throw cliError('CACHE_ERROR', 'failed to write device cache file', { path: runtimeConfig.cachePath, cause: error.message, }); } ``` ### Technical Analysis The CLI stores the bearer token in plaintext at `~/.aqa/config.json`. The configuration directory and file are created without explicit modes, leaving access permissions dependent on the process umask and any pre-existing file permissions. The same issue affects temporary and final device-cache files. The cache contains the complete `data` array ret ...[truncated 2050 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The file claims routing behavior but is associated with trait catalog parsing and local markdown file processing, which broadens its actual trust and data-handling surface. While lower impact than token/config mutation, this still creates review blind spots and could expose the agent to unintended local-file access not expected from a router-only skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The file claims routing behavior but is associated with trait catalog parsing and local markdown file processing, which broadens its actual trust and data-handling surface. While lower impact than token/config mutation, this still creates review blind spots and could expose the agent to unintended local-file access not expected from a router-only skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The file claims routing behavior but is associated with trait catalog parsing and local markdown file processing, which broadens its actual trust and data-handling surface. While lower impact than token/config mutation, this still creates review blind spots and could expose the agent to unintended local-file access not expected from a router-only skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The file claims routing behavior but is associated with trait catalog parsing and local markdown file processing, which broadens its actual trust and data-handling surface. While lower impact than token/config mutation, this still creates review blind spots and could expose the agent to unintended local-file access not expected from a router-only skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README documents aqara automations delete auto_abc123 --json as a common command, but does not warn that this operation deletes an automation and may be irreversible or affect home behavior. For markdown files, destructive or system-affecting behaviors should include a clear warning about impact on user data or system integrity.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill declares access to sensitive runtime inputs via environment variables and directs use of a network-capable CLI, but it does not define any explicit tool/permission scope limiting those capabilities. In an agent setting, missing scope boundaries can allow broader-than-expected secret access or outbound requests, increasing the blast radius if downstream child skills or prompt injection alter behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The language policy states that user-facing explanations, routing notes, and clarification questions should use Chinese Simplified. This enforces a specific language choice for all interactions, and the file does not offer the user any language or locale choice or document a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
- "what devices are in the living room" -> final intent is `device`
- "move all lights from the master bedroom to the second bedroom" -> final intent is `space`
- "create an automation that turns on the light when someone is in the living room" -> final intent is `automation`

## Shared Runtime Contract

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation says the user input is a double-press action and the analysis states ButtonEvent, is: "1" for double press, but the JSON starter uses "is": "0", which corresponds to single press. The note below further confirms that only single press is supported, so the example's stated intent contradicts the configuration it presents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file describes automations that will automatically turn off all lights and switches at a scheduled time, which can affect user-controlled devices and system behavior. The surrounding description presents the action as an example but does not include any caution or warning about unintended disruption if the wrong devices are targeted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The scheduled automation examples embed a specific locale setting, Asia/Shanghai, as if it were the default behavior. Because the file is general-purpose documentation rather than a region-specific tool, forcing one timezone without opt-in can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example describes a manually triggered automation that powers off all lights and switches, which could disrupt active devices or expected system state. The markdown includes no warning that activating the mode will issue batch power-off commands across multiple targets.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This general example uses Asia/Shanghai for a sunset-based schedule, imposing a locale-specific configuration in documentation that otherwise appears broadly applicable. Users in other regions could incorrectly inherit this setting, and the file does not offer a choice or justify the locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file includes ready-to-run commands that change real device and space state, such as toggling lights, changing brightness, creating spaces, updating spaces, and associating devices, without an explicit warning that these actions affect live environments. In an agent skill context, this increases the risk of unintended physical-world changes or unauthorized modifications when users or downstream agents copy examples directly into execution flows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file documents numerous writable traits such as camera sleep status, remote control enablement, door/garage controls, thermostat settings, and curtain motor controls, but provides no warning that changing these values can affect physical devices, privacy, or home security. Under the markdown-specific SQP-2 criteria, descriptions of behaviors that could affect user data, privacy, or system integrity should disclose such risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents a direct aqara automations delete command without requiring an explicit confirmation step, dry-run, or warning that deletion is irreversible. In an agent-executed workflow, this increases the chance that ambiguous user input, prompt injection, or simple operator error could cause destructive removal of home automations with no recovery path described.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This skill includes direct device-control workflows (ExecuteTraitRequest, aqara devices execute) without requiring any user-facing confirmation or warning that the action will change real physical device state. In a home-automation context, that increases the risk of unintended actuation of lights, switches, or other connected devices from ambiguous, mistaken, or socially engineered requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The documentation describes commands such as devices execute, spaces create/update/associate, and automation create/update/enable/disable flows that can change device behavior or home configuration, but it provides no general warning that these commands will affect real connected devices or automations. For markdown files, behaviors that can affect user data or system integrity should be clearly disclosed so users understand the operational impact before running them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents aqara automations delete operations, which are destructive and potentially irreversible, but it does not include any warning about the impact of deleting automations or advise users to verify targets before running the command. Under the markdown-file criteria for missing user warnings, destructive behaviors affecting user system state should be disclosed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code fetches device data from a remote service via postAqara and then writes a temporary cache file, deletes any existing cache file, and renames the new file into place. Within this file, there is no confirmation prompt, user-facing log/print, or comment/docstring disclosing that refresh transmits data over the network and replaces the local cache.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The devicesExecute command constructs a request and sends it via postAqara to ExecuteTraitRequest, which can change device state, but there is no confirmation step or warning before the network action occurs. Although results are printed afterward, there is no pre-execution disclosure that the command will transmit control data to a remote API and actuate a device.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The automationsDelete command issues a DeleteAutomationRequest, which is an irreversible operation, but this function contains no confirmation prompt, warning comment, or user-facing disclosure before executing it. In this code file, destructive operations should have some visible warning unless already clearly disclosed elsewhere, which is not evident here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document provides direct delete command examples for single and batch automation removal without adjacent warning language, confirmation guidance, or advice to verify targets before execution. In an agent-skill context, examples often become operational patterns, so omission of safety guardrails increases the chance of accidental destructive actions against home automations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description promises that the AC will start in cooling mode at 26 C. In code, the AC automation turns the unit on and writes the CoolingTemperature trait, but there is no action that explicitly sets an operating mode to cooling, so the implementation may not enforce the documented behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The metadata scope declares only a motion-sensor relationship, but the automations issue write actions to separate light and AC devices not explicitly included in scope. This creates an authorization and transparency gap: a reviewer or policy engine relying on declared scope could underestimate what the automation can control, enabling broader device actuation than advertised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.