Credential Access
- Category
- Privilege Escalation
- Confidence
- 95% confidence
- Finding
The skill instructs the user to create and use a Personal Access Token with broad read, write, and execute scopes over devices, locations, and scenes. In a direct-device-control skill, exposure or misuse of such a token could enable unauthorized surveillance of device state and execution of physical actions across the SmartThings environment.
- Content
smartthings locations # first call triggers login
text ### Personal Access Token (PAT) 1. Create a PAT at https://account.smartthings.com/tokens 2. Required scopes: `r:devices:*`, `w:devices:*`, `x:devices:*`, `r:locations:*`, `r:scenes:*`, `x:scenes:*`
