Back to skill

Security audit

Xiaomi Miot

Security checks for vulnerabilities and agentic risk

Overview

This Xiaomi smart-home skill is not clearly malicious, but it asks for full Xiaomi login credentials and stores/handles tokens in ways that need careful review before use.

Review this skill carefully before installing. Only use it if you are comfortable entering Xiaomi account credentials into the assistant or Feishu card, having a bearer token cached locally, and exposing CAPTCHA/login artifacts through Feishu. Prefer a version that uses an official delegated login flow, enforces secure token storage, removes hardcoded secrets, and actually scopes access to the device-control operations you need.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
login_card.py:211
Finding

Hard-Coded Xiaomi OAuth Client Secret

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
miot_service.py:31
Finding

Xiaomi Bearer Token Stored Without Enforced Access Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
login_card.py:181
Finding

Predictable Shared CAPTCHA File Enables Symlink and Race Attacks

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (28)

Tainted flow: 'APP_ID' from os.environ.get (line 16, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · login_card.py (reported line 21)May include surrounding context.

python
def get_tenant_token():
    """获取飞书 tenant token"""
    resp = requests.post(
        'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal',
        json={'app_id': APP_ID, 'app_secret': APP_SECRET},
        timeout=10

Tainted flow: 'CLIENT_ID' from os.environ.get (line 19, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · miot_service.py (reported line 90)May include surrounding context.

python
try:
        password_hash = hashlib.md5(password.encode()).hexdigest().upper()
        
        resp = requests.post(
            "https://account.xiaomi.com/oauth2/token",
            data={
                "client_id": CLIENT_ID,

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as an IoT control helper, but the behavior includes password login handling, challenge-response flow, persistent token caching, and device inventory retrieval. That broader account-access functionality materially changes the security posture because it can expose the user's Xiaomi account and all linked devices, not just execute a single device command.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as an IoT control helper, but the behavior includes password login handling, challenge-response flow, persistent token caching, and device inventory retrieval. That broader account-access functionality materially changes the security posture because it can expose the user's Xiaomi account and all linked devices, not just execute a single device command.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The login flow asks users to provide a Xiaomi phone number, password, and verification code in chat, yet the skill description does not prominently warn that highly sensitive credentials will be collected through the conversation. This creates a phishing-like pattern where users may disclose secrets without informed consent or understanding of how they are handled.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs the assistant to solicit and process the user's Xiaomi account password and verification code in plain chat. In the context of a smart-home skill, this is especially dangerous because compromise of those credentials can grant broad account access, device inventory visibility, and control over connected home devices, while chat logs, intermediaries, or plugins may capture the secrets.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code presents a Feishu card that asks the user to enter raw Xiaomi username and password directly into the skill. Collecting third-party account credentials inside a chat card is dangerous because it conditions users to disclose passwords to an intermediary service and gives the skill access to reusable credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill transmits Xiaomi account credentials or password-derived material to external Xiaomi endpoints without any user-facing disclosure, consent language, or security notice in this file. In the context of a device-control skill, silent handling of raw credentials is especially dangerous because users may not understand that full account authentication is occurring.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares no explicit tool scope even though its documented behavior requires environment variable access, network communication, and local file storage for token caching. Without a permissions boundary, an agent platform may grant broader-than-expected capabilities, increasing the blast radius if the skill is misused or compromised.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says the skill should be used when the user says phrases like “开灯” and “关空调”. These are common smart-home utterances without clear scoping to Xiaomi/Mi Home context, which may cause unintended invocation when users make general requests rather than explicitly targeting this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file reads FEISHU_APP_ID and FEISHU_APP_SECRET from environment variables to authenticate outbound API calls, but there is no user-facing notice that the skill depends on and uses platform credentials. For safety auditing, access to sensitive credentials should be accompanied by visible disclosure or documentation unless clearly covered elsewhere.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · login_card.py (reported line 21)May include surrounding context.

python
def get_tenant_token():
    """获取飞书 tenant token"""
    resp = requests.post(
        'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal',
        json={'app_id': APP_ID, 'app_secret': APP_SECRET},
        timeout=10

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · login_card.py (reported line 135)May include surrounding context.

python
def get_tenant_token():
    """获取飞书 tenant token"""
    resp = requests.post(
        'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal',
        json={'app_id': APP_ID, 'app_secret': APP_SECRET},
        timeout=10

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · login_card.py (reported line 21)May include surrounding context.

python
def get_tenant_token():
    """获取飞书 tenant token"""
    resp = requests.post(
        'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal',
        json={'app_id': APP_ID, 'app_secret': APP_SECRET},
        timeout=10

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The skill uploads a Xiaomi login captcha image to Feishu infrastructure. While not as severe as sending passwords, it still relays authentication-related material from one service into another platform, increasing exposure of the login process and potentially retaining artifacts outside the original trust boundary.

Content

Scanner excerpt · login_card.py (reported line 121)May include surrounding context.

python
token = get_tenant_token()
    
    with open(image_path, 'rb') as f:
        resp = requests.post(
            'https://open.feishu.cn/open-apis/im/v1/images',
            headers={'Authorization': f'Bearer {token}'},
            files={'image': ('captcha.png', f, 'image/png')},

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · login_card.py (reported line 135)May include surrounding context.

python
def send_card(token, open_id, card):
    """发送卡片消息"""
    resp = requests.post(
        'https://open.feishu.cn/open-apis/im/v1/messages?receive_id_type=open_id',
        headers={
            'Authorization': f'Bearer {token}',

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill goes beyond the declared smart-home control purpose and implements Xiaomi account login plus account-wide device enumeration. That expansion of scope is risky because it enables collection of full account access and inventory data, which is materially more sensitive than issuing device-control commands.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This request retrieves the user's Xiaomi device inventory from Xiaomi's API after obtaining account access. In context, it expands access from simple device control to broad account data collection, which is more dangerous than the manifest suggests and increases the privacy impact if the skill is abused or compromised.

Content

Scanner excerpt · login_card.py (reported line 256)May include surrounding context.

python
}
        
        resp2 = session.get(
            "https://api.io.mi.com/app/home/device/list",
            headers=headers,
            timeout=15
        )

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill requires the user's full Xiaomi account username and password and uses the OAuth password grant to obtain broad account access, which exceeds the narrow need implied by simple voice device control. In an agent-skill context, collecting primary credentials greatly increases blast radius if the skill, host, logs, or environment are compromised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says the skill is used to control Xiaomi smart-home devices such as lights, air conditioners, and robot vacuums. In this file, the implemented behavior is limited to Xiaomi account authentication, token caching, captcha handling, and fetching/listing devices; there is no code that sends control commands to devices.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Credential-derived authentication material is sent to external services and the resulting bearer-like token ('macaroon') is cached locally without any protection controls or user warning. If the cache file is read by another local user, process, backup, or malware, it can enable unauthorized access to the user's Xiaomi account and devices.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · miot_service.py (reported line 90)May include surrounding context.

python
try:
        password_hash = hashlib.md5(password.encode()).hexdigest().upper()
        
        resp = requests.post(
            "https://account.xiaomi.com/oauth2/token",
            data={
                "client_id": CLIENT_ID,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · miot_service.py (reported line 204)May include surrounding context.

python
"""用 macaroon token 获取设备列表"""
    try:
        resp = requests.get(
            "https://api.io.mi.com/app/home/device/list",
            headers={
                "Authorization": f"Bearer {macaroon}",
                "User-Agent": "Dalvik/2.1.0"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description and example invocation phrases are entirely in Chinese and imply a fixed interaction language. There is no indication that users may choose another language or that the Chinese-only behavior is a documented regional limitation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Publishing a fixed client ID is less severe than exposing a client secret, but it still contradicts the surrounding claim about not hardcoding values and may encourage copy-paste reuse of a shared application identity. Shared identifiers can complicate auditing, rate limiting, and isolation between deployments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.