Back to skill

Security audit

Roku Control

Security checks for vulnerabilities and agentic risk

Overview

This Roku-control skill does what it says, but it can send unauthenticated commands to devices on your local network, so users should only use it on trusted networks and approved Roku IPs.

Install only if you are comfortable letting the agent control Roku devices reachable from the same LAN. Use explicit, trusted Roku IP addresses rather than untrusted discovery results on shared or guest networks, and review disruptive actions such as power, app launch, volume, and text input before running them.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/roku_control.py:62
Finding

Unvalidated Network Destinations Enable Restricted SSRF and Unauthorized Device Control

Content
View full analysis
Dict[str, str]: """Get device info from a specific IP""" url = f"http://{ip}:{ROKU_PORT}/query/device-info" response = requests.get(url, timeout=2) ``` The manually supplied `--ip` value is also accepted without validation: ```python parser.add_argument("--ip", help="Roku device IP address") ``` ```python controller = RokuController(args.ip) ``` The unvalidated value is then used by information-query and state-changing operations: ```python url = f"http://{self.roku_ip}:{ROKU_PORT}/query/device-info" response = requests.get(url, timeout=5) ``` ```python url = f"http://{self.roku_ip}:{ROKU_PORT}/query/apps" response = requests.get(url, timeout=5) ``` ```python url = f"http://{self.roku_ip}:{ROKU_PORT}/keypress/{key}" response = requests.post(url, timeout=5) ``` ```python url = f"http://{self.roku_ip}:{ROKU_PORT}/launch/{app_id}" response = requests.post(url, timeout=5) ``` ```python for char in text: url = f"http://{self.roku_ip}:{ROKU_PORT}/keypress/Lit_ ...[truncated 3464 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
README.md:20
Finding

Unpinned Third-Party Dependency Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly promotes automatic discovery and control of Roku devices over the local network with no authentication, but does not warn that anyone or any automation on the same LAN can enumerate devices and issue disruptive commands such as app launching, text input, volume changes, and power control. In the context of an agent skill, this omission matters because it normalizes unauthenticated device control and may cause users to deploy it in shared, guest, or poorly segmented networks without understanding the privacy and abuse implications.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill performs LAN network actions against Roku devices but does not declare any explicit tool scope or permissions boundary. That makes the capability less transparent to the hosting agent and user, increasing the chance of unintended network access or execution in contexts that would otherwise require review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description advertises unauthenticated device control, including power and remote commands, without warning that the skill can change device state or interrupt active viewing. In an agent setting, that omission can cause users to invoke the skill without understanding it can immediately control nearby hardware on the LAN.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script issues real Roku ECP commands such as keypresses, app launches, power off, and text input over the local network without any confirmation, warning, or trust boundary check before performing the action. In an agent skill context, that means a prompt, misunderstanding, or prompt-injection-driven tool call could directly control a physical device and send unintended input to a TV session.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.