Back to skill

Security audit

Home Assistant CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent smart-home control documentation, but it needs Review because it encourages risky handling of powerful Home Assistant tokens and live device-control commands.

Install only if you are comfortable giving a CLI broad Home Assistant access. Use HTTPS with certificate verification, avoid storing long-lived tokens in shell startup files, never print or paste the token, prefer a secret manager or restricted config, and test state-changing commands only on verified non-critical entities with explicit user confirmation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:59
Finding

Long-Lived Home Assistant Token Stored in Plaintext Shell Configuration

Content
View full analysis
``` The surrounding instruction states that these values should be added to the user's shell configuration for persistence. The corresponding instructions in `README.md:43-49` are: ```bash export HASS_SERVER=http://your-homeassistant:8123 export HASS_TOKEN= ``` ### Technical Analysis A Home Assistant long-lived access token is a bearer credential: possession of the token is generally sufficient to authenticate as the issuing user. Persisting it directly in `~/.bashrc`, `~/.zshrc`, or another shell startup file leaves the secret in plaintext. Shell configuration files may be read by local software running as the user, copied into backups, included in support bundles, exposed through dotfile repositories, or displayed during troubleshooting. Every interactive shell also inherits the exported token, unnecessarily exposing it to child processes that do not need Home Assistant access. Because the documentation explicitly recommends persistence, this is not limited to a short-lived setup command; the credential remains exposed across sessions until manually removed or rotated. ### Attack Path 1. The user places the long-lived token in a shell startup file as instructed. 2. A malicious or compromised process running under the same account reads the startup file or inherited environment. 3. Alternatively, the shell file is copied into a backup, diagnostic archive, or public/private dotfile repository. 4. The attacker extracts `HASS_SERVER` and `HASS_TOKEN`. 5. The attacker submits authenticated requests to the Home Assistant API. 6. The attacker reads data or invokes device-control services ...[truncated 575 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/troubleshooting.md:22
Finding

Troubleshooting Instructions Expose the Access Token Through Output and Process Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
README.md:43
Finding

Plaintext HTTP and TLS Verification Bypass Can Expose Authentication and Control Traffic

Content
View full analysis
``` From `references/troubleshooting.md:36-45`: ```bash hass-cli --insecure info ``` ```bash hass-cli --cert /path/to/cert.pem info ``` ### Technical Analysis The README demonstrates a Home Assistant endpoint over plaintext HTTP. When bearer authentication is used over an unencrypted connection, network observers can potentially capture credentials and API traffic. The troubleshooting guide also recommends `--insecure`, which disables TLS certificate verification. Although this encrypts traffic, it removes reliable server authentication and permits a man-in-the-middle attacker to impersonate the Home Assistant server using an untrusted certificate. The certificate-based alternative is safer, but the guide presents the verification bypass as a normal solution without clearly restricting it to temporary diagnostics on a trusted network or warning that credentials must not be used while verification is disabled. ### Attack Path 1. The user configures the documented `http://` endpoint or invokes `hass-cli --insecure`. 2. The user connects across a network accessible to an attacker, such as a compromised LAN, malicious access point, shared network, or intercepted routing path. 3. For HTTP, the attacker observes unencrypted authentication and API traffic. 4. For `--insecure`, the attacker presents an untrusted certificate and proxies the connection. 5. The attacker captures the bearer token or alters Home Assistant requests and responses. 6. The captured token is replayed to access Home Assistant, or proxied commands are manipulated in transit. ### Impact Assessment A successful network interception ma ...[truncated 481 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (15)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 56)May include surrounding context.

md
**Get your token:**
1. Open Home Assistant web interface
2. Click your profile (bottom left)
3. Scroll to "Long-Lived Access Tokens"
4. Click "CREATE TOKEN"
5. Copy the token (only shown once!)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
**Get your token:**
1. Open Home Assistant web interface
2. Click your profile (bottom left)
3. Scroll to "Long-Lived Access Tokens"
4. Click "CREATE TOKEN"
5. Copy the token (only shown once!)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 127)May include surrounding context.

md
Before using hass-cli, configure authentication:

1. Generate a long-lived access token in Home Assistant:
   - Navigate to your profile: `https://your-homeassistant:8123/profile`
   - Scroll to "Long-Lived Access Tokens"
   - Create a new token

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
Before using hass-cli, configure authentication:

1. Generate a long-lived access token in Home Assistant:
   - Navigate to your profile: `https://your-homeassistant:8123/profile`
   - Scroll to "Long-Lived Access Tokens"
   - Create a new token

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 22)May include surrounding context.

  1. Verify Home Assistant is running:
    bash
    curl $HASS_SERVER/api/
    # Should return: {"message": "API running."}
    

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 165)May include surrounding context.

hass-cli service --help

text

2. **Enable debug mode:**
```bash
hass-cli --debug state list

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation instructs users to place a long-lived Home Assistant token in persistent shell configuration via an environment variable, but gives no warning about credential exposure through shell history, local file disclosure, process inspection in some environments, or accidental inclusion in backups/dotfile sync. A long-lived token can grant broad control over the home automation system if stolen.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README provides direct device-control examples such as turning lights on/off and changing brightness without any caution that these commands affect real physical devices and home state. In an agent-skill context, this increases the chance of unintended or unsafe actuation, especially if a user or downstream agent treats the examples as harmless exploration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup instructions tell users to generate a long-lived access token and export it into environment variables without warning that the token is a sensitive credential. This increases the chance of accidental disclosure through shell history, screenshots, shared shell profiles, process/environment leakage, or reuse in insecure contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation includes multiple service-call examples that actively change device state, such as turning lights and switches on or off, but it does not warn users that copying these commands will perform real actions in their home. In a smart-home context, omission of an action-safety warning can lead to unintended physical effects, disruption, or unsafe actuation of connected devices.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The examples directly invoke Home Assistant services that can change the physical environment or security posture of a home, such as opening blinds, turning devices on, and triggering automations, without any warning that they should only be used on trusted systems and verified entity IDs. In an agent skill context, copy-pasteable commands like these can normalize unsafe execution and make it easier for users or downstream agents to perform unintended real-world actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The troubleshooting guide instructs users to print the full Home Assistant long-lived token with echo $HASS_TOKEN, explicitly revealing a live credential on screen and potentially into terminal scrollback, screen recordings, shared shells, or support transcripts. In a Home Assistant control skill, that token typically grants broad API access, so exposing it increases the risk of account or automation compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill advertises event watching and history queries without warning that these features expose occupancy patterns, device usage, and other household activity data. In a home-automation setting, even read-only observability can reveal sensitive behavioral information if logs or outputs are shared or monitored carelessly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The markdown tells users to append an eval-based completion command to ~/.bashrc and then source the file, which changes persistent shell configuration and immediately executes the updated script. There is no user-facing warning about reviewing the generated command or the effect of modifying shell startup files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The instructions direct the user to add an eval command to ~/.zshrc and then source it, which persists changes to the shell environment and runs the code immediately. The document does not disclose this impact or advise caution before applying the change.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.