T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is coherent smart-home control documentation, but it needs Review because it encourages risky handling of powerful Home Assistant tokens and live device-control commands.
Install only if you are comfortable giving a CLI broad Home Assistant access. Use HTTPS with certificate verification, avoid storing long-lived tokens in shell startup files, never print or paste the token, prefer a secret manager or restricted config, and test state-changing commands only on verified non-critical entities with explicit user confirmation.
SKILL.md:14Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk
SKILL.md:59Long-Lived Home Assistant Token Stored in Plaintext Shell Configuration
references/troubleshooting.md:22Troubleshooting Instructions Expose the Access Token Through Output and Process Arguments
README.md:43Plaintext HTTP and TLS Verification Bypass Can Expose Authentication and Control Traffic
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**Get your token:**
1. Open Home Assistant web interface
2. Click your profile (bottom left)
3. Scroll to "Long-Lived Access Tokens"
4. Click "CREATE TOKEN"
5. Copy the token (only shown once!)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**Get your token:**
1. Open Home Assistant web interface
2. Click your profile (bottom left)
3. Scroll to "Long-Lived Access Tokens"
4. Click "CREATE TOKEN"
5. Copy the token (only shown once!)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Before using hass-cli, configure authentication:
1. Generate a long-lived access token in Home Assistant:
- Navigate to your profile: `https://your-homeassistant:8123/profile`
- Scroll to "Long-Lived Access Tokens"
- Create a new token
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Before using hass-cli, configure authentication:
1. Generate a long-lived access token in Home Assistant:
- Navigate to your profile: `https://your-homeassistant:8123/profile`
- Scroll to "Long-Lived Access Tokens"
- Create a new token
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
curl $HASS_SERVER/api/
# Should return: {"message": "API running."}
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
hass-cli service --help
2. **Enable debug mode:**
```bash
hass-cli --debug state list
The documentation instructs users to place a long-lived Home Assistant token in persistent shell configuration via an environment variable, but gives no warning about credential exposure through shell history, local file disclosure, process inspection in some environments, or accidental inclusion in backups/dotfile sync. A long-lived token can grant broad control over the home automation system if stolen.
The README provides direct device-control examples such as turning lights on/off and changing brightness without any caution that these commands affect real physical devices and home state. In an agent-skill context, this increases the chance of unintended or unsafe actuation, especially if a user or downstream agent treats the examples as harmless exploration.
The setup instructions tell users to generate a long-lived access token and export it into environment variables without warning that the token is a sensitive credential. This increases the chance of accidental disclosure through shell history, screenshots, shared shell profiles, process/environment leakage, or reuse in insecure contexts.
The documentation includes multiple service-call examples that actively change device state, such as turning lights and switches on or off, but it does not warn users that copying these commands will perform real actions in their home. In a smart-home context, omission of an action-safety warning can lead to unintended physical effects, disruption, or unsafe actuation of connected devices.
The examples directly invoke Home Assistant services that can change the physical environment or security posture of a home, such as opening blinds, turning devices on, and triggering automations, without any warning that they should only be used on trusted systems and verified entity IDs. In an agent skill context, copy-pasteable commands like these can normalize unsafe execution and make it easier for users or downstream agents to perform unintended real-world actions.
The troubleshooting guide instructs users to print the full Home Assistant long-lived token with echo $HASS_TOKEN, explicitly revealing a live credential on screen and potentially into terminal scrollback, screen recordings, shared shells, or support transcripts. In a Home Assistant control skill, that token typically grants broad API access, so exposing it increases the risk of account or automation compromise.
The skill advertises event watching and history queries without warning that these features expose occupancy patterns, device usage, and other household activity data. In a home-automation setting, even read-only observability can reveal sensitive behavioral information if logs or outputs are shared or monitored carelessly.
The markdown tells users to append an eval-based completion command to ~/.bashrc and then source the file, which changes persistent shell configuration and immediately executes the updated script. There is no user-facing warning about reviewing the generated command or the effect of modifying shell startup files.
The instructions direct the user to add an eval command to ~/.zshrc and then source it, which persists changes to the shell environment and runs the code immediately. The document does not disclose this impact or advise caution before applying the change.
No suspicious patterns detected.