Back to skill

Security audit

Mijia

Security checks for vulnerabilities and agentic risk

Overview

The skill openly controls a configured Xiaomi Mijia lamp as advertised, with real-world device-control and dependency risks users should understand before enabling it.

Install only if you are comfortable giving the agent control over the configured Mijia device. Prefer requiring explicit confirmation before power, brightness, temperature, or mode changes, pin and lock dependencies before use, and run it with only the needed Xiaomi account/device access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
pyproject.toml:6
Finding

Unbounded Authentication-Capable Third-Party Dependency

Content
View full analysis
=3.0.5", ] ``` The installation instructions in `README.md:36-40` and `SKILL.md:14-18` direct users to resolve and install this dependency: ```bash uv sync ``` No reviewed lockfile is present in the audited project. ### Technical Analysis The version constraint only establishes a minimum version and permits the package resolver to install any later release satisfying `>=3.0.5`. Because no lockfile or integrity-pinned artifact is included, two installations at different times may receive different dependency code without any corresponding change to this project. This is security-sensitive because `scripts/lamp_cli.py` imports `mijiaAPI` and invokes its authentication and device-control interfaces. An eligible release compromised at the upstream repository, package registry, maintainer account, or build pipeline could therefore execute within the CLI process and interact with authentication state and smart-home operations. The audit did not establish that the current `mijiaapi` package is malicious. The finding concerns the project's unsafe dependency resolution policy and the absence of a reproducible, reviewed dependency set. ### Attack Path 1. An attacker compromises the package publisher, distribution account, release pipeline, or another eligible dependency release. 2. The attacker publishes a malicious version that satisfies `mijiaapi>=3.0.5`. 3. A user follows the documented installation process and runs `uv sync`. 4. The resolver selects and installs the malicious eligible version because no reviewed lockfile or exact integrity constraint prevents version drift. 5. The CLI imports the package and calls `mijiaAPI()` and `api.login()`. 6. Malicious dependency code executes with the privileges and environment of ...[truncated 671 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/lamp_cli.py:121
Finding

Color Temperature Range Is Documented but Not Enforced

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README encourages natural-language control of real smart-home devices but does not clearly warn that agent-issued commands can directly change physical device state. In an AI-agent context, this increases the risk of accidental or prompt-induced actions such as switching devices on/off or changing modes without the user's fully informed consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill references and depends on an environment variable (MIJIA_LAMP_DID) and operational shell commands, but it does not declare any explicit tool scope or permission boundary. That creates an authorization ambiguity where an agent may access environment data or execute capability-bearing steps without a clearly constrained contract, increasing the risk of unintended secret access or unsafe execution behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill maps natural-language requests directly to state-changing smart-home commands such as turning devices on/off and changing modes, but provides no confirmation, safety checks, or user-warning guidance. In an agent setting, this can cause unintended physical-world actions from ambiguous, spoofed, or accidental prompts, especially because device control affects real hardware.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest describes a skill for controlling Mijia devices such as lamps and plugs, but this file additionally depends on process environment configuration to obtain the target device ID. Reading environment variables is not described in the manifest and introduces access to host-level configuration outside the stated control actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.