Back to skill

Security audit

Accessibility Toolkit

Security checks for vulnerabilities and agentic risk

Overview

The skill is a documentation-only accessibility toolkit, but it gives unsafe smart-home guidance for locks and access codes that users should review before adopting.

Review this skill before installing or following its examples. Do not use the door-unlock automation as written; require explicit authorization, multiple trusted presence signals, time limits, notifications, and automatic relocking. Do not put real access codes in agent responses, logs, or prompts. If using the conversation-history audit idea, keep it opt-in and local where possible, minimize retained data, and redact sensitive health, schedule, and home details.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:35
Finding

Security-Sensitive Door Unlocking Without Explicit Confirmation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:35, 80-93
Vulnerability Type: Unsafe authorization and confirmation policy for physical-security automation
Risk Level: Medium

Vulnerable Code

markdown
**Never require confirmation for reversible actions.** Just do it. They can say "undo" if wrong.
yaml
automation:
  - alias: "Home Arrival - Accessible"
    trigger:
      - platform: zone
        entity_id: person.human
        zone: zone.home
        event: enter
    action:
      - service: scene.turn_on
        target:
          entity_id: scene.welcome_home
      - service: lock.unlock
        target:
          entity_id: lock.front_door
      - service: notify.agent
        data:
          message: "Human is home. Unlocked front door."

Technical Analysis

The Skill establishes a broad rule that reversible actions should not require confirmation, then provides an automation that unlocks a front door based solely on an arrival event. Although unlocking can technically be reversed by relocking the door, it creates an immediate physical-security exposure that cannot be undone if an unauthorized person enters.

Zone and presence signals are not sufficient authorization boundaries by themselves. Depending on the deployment, they may be affected by stale device state, GPS inaccuracies, account compromise, sensor errors, or spoofed presence data. The template does not require device authentication, corroborating sensors, proximity verification, or explicit user approval before operating the lock.

The repository contains documentation and configuration examples rather than an active deployment. Exploitation therefore requires a user or agent to adopt this template in a Home Assistant environment.

Attack Path

  1. A user or agent implements the documented arrival automation.
  2. The person.human entity incorrectly or maliciously transitions into zone.home ...[truncated 846 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the blanket no-confirmation rule with a risk-based policy.
  • Restrict confirmation-free execution to a narrow allowlist of low-impact actions, such as changing lights or media playback.
  • Require explicit user authorization for locks, alarms, garage doors, purchases, external communications, and other consequential operations.
  • For accessibility-sensitive workflows where repeated confirmation is burdensome, use a preauthorized policy with narrowly defined devices, time windows, users, and conditions.
  • Require multiple trusted presence signals, such as authenticated phone proximity plus an occupancy sensor, rather than relying on one zone transition.
  • Add a short timeout, automatic relocking, event logging, and an immediate security notification.
  • Fail closed when presence information is stale, ambiguous, unavailable, or inconsistent.
  • Preserve an accessible emergency override that is authenticated and does not weaken routine access controls.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:136
Finding

Plaintext Disclosure Pattern for a Physical Access Code

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:136-142
Vulnerability Type: Plaintext sensitive credential exposure
Risk Level: Medium

Vulnerable Code

text
❌ Smart lock offline (last seen 10min ago)
   → Manual backup: code is 4821
   → I'll alert when it reconnects

Technical Analysis

The error-reporting example places a door access code directly in agent output. The value appears to be illustrative rather than a confirmed production credential, but the template promotes an unsafe handling pattern if replaced with a real code.

Agent responses may be retained in conversation history, application telemetry, backups, notification logs, lock-screen previews, or monitoring systems. They may also be displayed or spoken where unauthorized people can observe them. A physical access credential should not be included in routine status output merely because the smart lock is offline.

This repository does not contain credential-storage or notification code, so no actual secret exfiltration was confirmed. The risk arises when an agent follows the documented pattern with a real backup code.

Attack Path

  1. A user or integrator adapts the example and substitutes a real door code.
  2. The smart lock becomes unavailable or is made to appear offline.
  3. The agent generates the documented error response containing the plaintext code.
  4. The response is exposed through chat history, logs, screen previews, spoken output, or notifications.
  5. An unauthorized observer retrieves the code.
  6. The observer uses the code to gain physical access before it is rotated or revoked.

Impact Assessment

Exposure can reveal a reusable physical access credential to anyone able to view the relevant response or downstream logs. This may permit unauthorized entry to the protected property and can endanger occupants or property. The issue does not itself provide system-level privileges, and its practical impact d ...[truncated 99 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove access codes and other credentials from routine status and error-reporting templates.
  • Store physical access credentials in an approved secret manager rather than documentation, prompts, automation files, or conversation history.
  • Only reveal recovery credentials after an authenticated, user-initiated request and an appropriate step-up verification.
  • Prefer a secure out-of-band recovery mechanism over displaying or speaking a reusable code.
  • Redact secrets from logs, telemetry, notifications, lock-screen previews, and conversation retention.
  • Use temporary, single-use, or rapidly expiring access credentials where the lock platform supports them.
  • Audit access-code retrieval and immediately rotate a code after suspected disclosure.
  • Replace the example with non-sensitive guidance such as: Manual backup access is available through your authenticated recovery method.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The arrival automation automatically unlocks the front door on zone entry without discussing authentication strength, spoofing risk, geolocation errors, or user consent boundaries. Because this directly affects physical security, unsafe examples in documentation can lead operators to deploy an automation that enables unauthorized entry if presence detection is inaccurate or compromised.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The guidance says to never require confirmation for reversible actions and to "just do it," which promotes autonomous execution in response to voice input without sufficient guardrails. In an accessibility skill controlling home functions, misrecognition or accidental triggers can still cause meaningful harm even when actions are theoretically reversible, especially when users may have limited ability to promptly issue an undo command.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

"Goodnight" → Bedtime scene, lock doors, set thermostat, silence notifications "I'm working" → Focus mode, desk lights, DND, close distracting tabs "Movie time" → Dim lights, TV on, adjust audio "Help" → Immediate attention, no confirmation dialogs

text

**Never require confirmation for reversible actions.** Just do it. They can say "undo" if wrong.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command phrase "Help" is extremely broad and is paired with "Immediate attention, no confirmation dialogs," which creates ambiguity about what actions may be triggered during distress or accidental activation. In a voice-first accessibility context, broad unauthenticated triggers increase the chance of false activations, social engineering, or unintended emergency/automation behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

✓ Doors locked ✓ Thermostat 68°F

No confirmation needed — all reversible with one word.

text

## Scripts

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script description states it analyzes conversation history to find repeated requests, but it gives no notice about retention, consent, local vs. remote processing, or handling of sensitive disability-related information. In this context, conversation logs may contain health routines, schedules, home details, and other sensitive data, so omission of privacy guidance can result in overcollection or unsafe storage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.