Back to skill

Security audit

Tessie Tesla Control

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Tessie/Tesla integration, but it can access sensitive vehicle location data and issue real vehicle-control commands without enough guardrails, and its API endpoint override can expose the Tessie bearer key.

Install only if you are comfortable giving the skill access to your Tessie account and vehicle telemetry. Treat it as capable of controlling a real car: review commands before running them, avoid using it in shared or automated agent contexts, do not set TESSIE_API_URL unless you fully trust the endpoint, and prefer a Tessie API key with the narrowest permissions available.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
tessie.sh:9
Finding

Bearer Credential Disclosure Through an Unrestricted API Endpoint Override

Content
View full analysis

Vulnerability Details

File Location: tessie.sh:9 and tessie.sh:86-99
Vulnerability Type: Arbitrary credential transmission destination
Risk Level: High

Vulnerable Code

bash
# Configuration from env or fallback
TESSIE_API_URL="${TESSIE_API_URL:-https://api.tessie.com}"
TESSIE_API_KEY="${TESSIE_API_KEY:-}"
bash
# Helper: Make API request
api_request() {
    local method="$1"
    local endpoint="$2"
    local data="${3:-}"

    if [[ -n "$data" ]]; then
        curl -s --fail --max-time 30 \
            -H "Authorization: Bearer $TESSIE_API_KEY" \
            -H "Content-Type: application/json" \
            -d "$data" \
            "${TESSIE_API_URL}${endpoint}" 2>/dev/null
    else
        curl -s --fail --max-time 30 \
            -H "Authorization: Bearer $TESSIE_API_KEY" \
            "${TESSIE_API_URL}${endpoint}" 2>/dev/null
    fi
}

Technical Analysis

The destination receiving the Tessie bearer credential is controlled by the TESSIE_API_URL environment variable. The script does not validate the URL scheme, hostname, port, or presence of URL user information before attaching the Authorization header.

Although the default destination is the legitimate HTTPS endpoint https://api.tessie.com, a modified runtime environment can redirect every API request to an arbitrary server. An http:// value can additionally cause the credential and request metadata to be transmitted without TLS.

Network communication with Tessie is necessary for the declared functionality. Allowing an unrestricted destination override is not necessary and exceeds the minimum privilege required. This also contradicts the assertion in SECURITY_AUDIT.md that HTTPS is enforced.

Attack Path

  1. An attacker gains influence over the environment used to launch the Skill, such as a wrapper, automation configuration, inherited process environment, or deployment setting.

...[truncated 1292 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the TESSIE_API_URL override if alternate API hosts are not an explicit requirement:

    bash
    readonly TESSIE_API_URL="https://api.tessie.com"
    
  2. If configurability is required, strictly allowlist the exact production origin before making any request:

    bash
    TESSIE_API_URL="${TESSIE_API_URL:-https://api.tessie.com}"
    
    if [[ "$TESSIE_API_URL" != "https://api.tessie.com" ]]; then
        echo "Unsupported Tessie API endpoint" >&2
        exit 1
    fi
    
  3. Reject non-HTTPS schemes, URL user information, unexpected ports, redirects to untrusted hosts, and malformed URLs.

  4. Add curl hardening controls:

    bash
    curl --silent --show-error --fail --max-time 30 \
        --proto '=https' \
        --tlsv1.2 \
        -H "Authorization: Bearer $TESSIE_API_KEY" \
        -- "${TESSIE_API_URL}${endpoint}"
    
  5. If redirects are enabled in the future, ensure authorization headers cannot be forwarded to another origin.

  6. Add automated tests verifying that HTTP URLs, lookalike domains, alternate ports, user-information URLs, and arbitrary hosts are rejected before the authorization header is transmitted.

  7. Revoke and rotate any Tessie credential that may have been used while an untrusted TESSIE_API_URL value was present.

T09 · Insecure Skill Coding Practices

Note
Location
tessie.sh:224
Finding

Unfiltered Tessie API Responses May Expose Sensitive Vehicle Metadata

Content
View full analysis

Vulnerability Details

File Location: tessie.sh:224-236; the same pattern is repeated at lines 256, 270, 313, 327, 348, 362, 382, and 401
Vulnerability Type: Sensitive information exposure through error output
Risk Level: Low

Vulnerable Code

bash
preheat|heat|warm)
    # Preheat car
    get_vehicle_info
    echo "🔥 Starting climate..."

    PAYLOAD=$(jq -n --arg t "$TEMP" '{temperature: $t}')
    RESULT=$(api_request "POST" "/${TESSIE_VIN}/command/start_climate" "$PAYLOAD")

    if [[ $? -eq 0 ]]; then
        echo "✅ Climate started"
    else
        echo "⚠️  Failed to start climate"
        echo "Response: $RESULT"
    fi
    ;;

Equivalent raw-response output occurs in several other command failure branches:

bash
echo "Response: $RESULT"

Technical Analysis

Multiple command handlers print the complete contents of RESULT when an operation fails. The response is not passed through a field allowlist or redaction routine before being written to standard output.

Tessie responses may include vehicle identifiers, VINs, state information, command details, or other account and vehicle metadata. Printing the response verbatim can propagate that information into terminal history, agent transcripts, orchestration logs, monitoring systems, or support records.

The current script also contains unrelated functional defects—such as undefined get_vehicle_id and unset TEMP usage—that prevent some affected branches from being reached as intended. Nevertheless, the raw-response sinks remain present and would become active if those command defects are corrected. A reachable command that receives a successful HTTP response containing an API-level failure object could also expose that object.

Attack Path

  1. A command reaches one of the affected API request branches.
  2. Tessie or a configured API endpoint returns a response representing a command failure or other con ...[truncated 1005 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not print complete API responses during normal operation. Return a fixed, non-sensitive error message:

    bash
    echo "Failed to execute the Tessie command" >&2
    
  2. Parse a narrowly allowlisted error field when useful:

    bash
    SAFE_ERROR=$(printf '%s' "$RESULT" | jq -r '.error.code // "request_failed"')
    printf 'Command failed: %s\n' "$SAFE_ERROR" >&2
    
  3. Add an explicit, opt-in debug mode rather than emitting diagnostic responses by default.

  4. Before debug output is displayed, redact bearer tokens, VINs, vehicle IDs, coordinates, addresses, saved locations, email addresses, and other account metadata.

  5. Send errors to standard error and document that debug output may contain sensitive information.

  6. Apply the remediation consistently to all raw-response output at lines 235, 256, 270, 313, 327, 348, 362, 382, and 401.

  7. Add tests using responses populated with synthetic sensitive fields to verify that no such fields appear in normal command output.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

The script explicitly attempts to access credentials from a local clawdbot configuration file, which is credential harvesting behavior in the context of an agent skill. Because the recovered API key can control and locate a vehicle, unauthorized secret use could enable remote monitoring and vehicle actions.

Content

Scanner excerpt · tessie.sh (reported line 12)May include surrounding context.

sh
TESSIE_API_URL="${TESSIE_API_URL:-https://api.tessie.com}"
TESSIE_API_KEY="${TESSIE_API_KEY:-}"

# Get API key from clawdbot config if env not set
if [[ -z "$TESSIE_API_KEY" ]]; then
    CONFIG_FILE="$HOME/.clawdbot/clawdbot.json"
    if [[ -f "$CONFIG_FILE" ]]; then

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tessie.sh (reported line 439)May include surrounding context.

sh
./tessie.sh fsd-week

Setup:
  1. Get API key from https://tessie.com/developers
  2. Set TESSIE_API_KEY env var or add to clawdbot.json
  3. Optionally set TESSIE_VEHICLE_ID if known
EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SECURITY_AUDIT.md (reported line 38)May include surrounding context.

md
**Assessment**: ✅ SECURE
- API key not hardcoded in script
- Read from secure config via jq
- Used in curl Authorization header only
- Not echoed or logged directly

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The audit explicitly notes that full API responses may still be printed for debugging, and those responses can contain vehicle metadata. Even though this is only documentation, it indicates the underlying skill may expose sensitive operational or location-related data to logs or users without a clear opt-in, which is a real information disclosure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises remote vehicle-control features such as climate and charging control, along with access to precise location and drive history, but provides no user-facing warning about the safety, security, or privacy implications of invoking these actions. In an agent setting, this increases the risk of unsafe or unintended commands affecting a physical asset and exposing sensitive telemetry without informed consent or confirmation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

This endpoint sends authenticated requests to a third-party service and returns full vehicle data with embedded last_state, which may include sensitive telemetry such as location, status, and identifiers. External transmission is expected for this integration, but it still represents a real privacy and credential-handling risk if users are not clearly informed and if responses are over-collected.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

Get Vehicles

text
GET https://api.tessie.com/vehicles

Returns full vehicle list with last_state embedded

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

The drives endpoint transmits a VIN to a third-party API and retrieves recent trip history, including potentially sensitive location and movement patterns. In the context of a vehicle skill, drive history is highly privacy-sensitive because it can reveal home, work, routines, and absences.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

Get Drives

text
GET https://api.tessie.com/{VIN}/drives?limit=10

Returns recent drive history

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The idles endpoint retrieves parked-session data, including climate and sentry usage, from an external service using the VIN. This can expose patterns about when and where the vehicle is stationary, creating privacy and physical-security concerns if mishandled.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

Get Idles

text
GET https://api.tessie.com/{VIN}/idles?limit=10

Returns parked sessions with climate/sentry usage

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The command endpoint enables authenticated remote actions against a physical vehicle using its VIN, including locking, unlocking, trunk activation, window control, climate, charging, and sentry settings. In an agent context, exposing remote actuation of a real-world asset without explicit safety controls, confirmation, or authorization boundaries creates a significant risk of unauthorized or accidental physical actions.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

Commands

All control commands use VIN (not vehicle_id):

text
POST https://api.tessie.com/{VIN}/command/{command}

Available commands:

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script automatically reads a Tessie API key and vehicle ID from a local clawdbot configuration file, creating implicit credential access outside the script's direct input surface. In an agent-skill context, this is dangerous because simply invoking the skill can cause it to harvest sensitive local secrets and use them for remote vehicle access without an explicit opt-in at runtime.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tessie.sh (reported line 91)May include surrounding context.

sh
local data="${3:-}"

    if [[ -n "$data" ]]; then
        curl -s --fail --max-time 30 \
            -H "Authorization: Bearer $TESSIE_API_KEY" \
            -H "Content-Type: application/json" \
            -d "$data" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The location command fetches and prints precise latitude and longitude without any warning, confirmation, or minimization. In an agent setting, exposing live vehicle location is highly sensitive and can disclose home, work, or travel patterns if the output is logged, shared, or surfaced to other tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script exposes remote vehicle-control actions such as climate control, charging, and charge-limit changes with no confirmation guardrails and little user-facing caution. In a skill ecosystem, these commands can trigger real-world actions on a vehicle, making accidental or unauthorized execution materially more dangerous than ordinary API operations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The inline comment states 'Basic UUID format check (version 4 UUID)', which implies a version-specific validation. The regex that follows only checks a generic lowercase UUID layout and does not enforce the version-4 nibble or variant, so the documentation actively misdescribes what the code verifies.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.