Back to skill

Security audit

SmartThings Direct

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent and not malicious, but it gives an agent broad, persistent authority to directly control real SmartThings devices, so it deserves user review.

Install only if you want an agent to directly control your SmartThings environment. Prefer browser OAuth over PATs when possible, avoid broad PAT use for casual read-only tasks, keep CLI config files private, revoke tokens when no longer needed, and require explicit confirmation before scenes, HVAC, locks, security devices, or other consequential actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill instructs the user to create and use a Personal Access Token with broad read, write, and execute scopes over devices, locations, and scenes. In a direct-device-control skill, exposure or misuse of such a token could enable unauthorized surveillance of device state and execution of physical actions across the SmartThings environment.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

smartthings locations # first call triggers login

text

### Personal Access Token (PAT)

1. Create a PAT at https://account.smartthings.com/tokens
2. Required scopes: `r:devices:*`, `w:devices:*`, `x:devices:*`, `r:locations:*`, `r:scenes:*`, `x:scenes:*`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
scripts/st-find.sh "living room"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger description is broad enough to invoke this skill whenever users mention generic terms like 'smartthings' or 'ST', which can route requests into a powerful direct-control path unnecessarily. In this context, unintended invocation is risky because the skill can perform real device actions against a SmartThings hub, including state-changing commands and scene execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill describes itself as a low-level direct-control path that bypasses Home Assistant, but it does not prominently warn that commands can immediately change physical device state. That omission increases the chance an agent or operator will use it casually for destructive or safety-relevant actions such as HVAC, lights, or scenes without explicit confirmation.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

Browser (preferred)

Run any command — the CLI opens a browser for Samsung account OAuth on first use.

bash
smartthings locations      # first call triggers login

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill recommends storing a PAT in a persistent CLI config file, which creates durable credential presence on disk for a tool capable of issuing direct device and scene commands. If that host or user profile is compromised, the stored token can be reused to control SmartThings resources without additional authentication until expiry or revocation.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

Personal Access Token (PAT)

  1. Create a PAT at https://account.smartthings.com/tokens
  2. Required scopes: r:devices:*, w:devices:*, x:devices:*, r:locations:*, r:scenes:*, x:scenes:*
  3. Either pass per command:
    bash

Static analysis

No suspicious patterns detected.