Back to plugin

Security audit

Home Assistant Agent Interface

Security checks across malware telemetry and agentic risk

Overview

This Home Assistant skill can control real devices, but that capability is coherent with its purpose and is disclosed in the package materials.

Install only with a Home Assistant token whose permissions you are comfortable giving to an agent. Use a limited Home Assistant user/token where possible, be cautious with locks, alarms, garage doors, HVAC, scripts, and automations, and prefer SecretRef configuration rather than storing the token directly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to perform direct Home Assistant control actions, including executing actions against household devices, but the description does not warn users that it can change the physical environment. This omission can mislead users about the capability and risk surface of the skill, increasing the chance of unintended device operation such as unlocking, disabling alarms, or changing safety-relevant settings.

VirusTotal

61/61 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.