Back to skill

Security audit

Daikin Aircon Controller

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real Daikin AC controller, but it stores device credentials locally and can send network traffic to user-supplied addresses, so it should be reviewed before installation.

Install only if you are comfortable with this skill controlling HVAC devices on your network and storing AC IPs plus any API keys or passwords in a local JSON file. Use it only on networks and devices you own or administer, avoid shared workspaces for real credentials, and prefer a version that validates local device addresses, clears credentials when changing IPs, restricts file permissions, and pins dependencies.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/config.ts:54
Finding

Device API Keys and Passwords Are Persisted in Plaintext Without Enforced Access Restrictions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/tools/devices.ts:273
Finding

Unvalidated Device Destinations Permit Arbitrary Network Targeting and Credential Redirection

Content
View full analysis
= {}; if (params.newIp) updates.ip = params.newIp; if (params.newName) { updates.name = params.newName; updates.id = params.newName.toLowerCase().replace(/\s+/g, '-'); } if (params.type) updates.type = params.type; if (params.key) updates.key = params.key; if (params.password) updates.password = params.password; ``` The configured destination and credentials are then passed to the network library: ```ts const options: { key?: string; password?: string } = {}; if (config.key) options.key = config.key; if (config.password) options.password = config.password; const device = await DaikinFactory(config.ip, { deviceId: config.ip, ...options, }); ``` Discovery also accepts an unrestricted target: ```ts private getBroadcastIps(targetIp?: string): string[] { if (targetIp) { return [targetIp]; } ``` ### Technical Analysis The tool schema only requires `ip` and `targetIp` to be strings. There is no runtime parsing or policy enforcement to ensure that a destination: - Is a valid IP literal. - Belongs to an approved private or local subnet. - Is a broadcast address where discovery requires one. - Is not a loopback, multicast, unspecified, link-local, public, or other sensitive address. - Corresponds to the intended Daikin appliance. The `daikin_update` flow is particularly sensitive. Changing `newIp` does not clear an API key or password alr ...[truncated 2880 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill description presents the capability as simple AC control, but the documented behavior also includes device inventory management and handling of sensitive data such as IP addresses, API keys, and passwords. That mismatch can cause users to disclose credentials and network-identifying information without clear informed consent, and it broadens the skill from control into persistent secret management.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description presents the capability as simple AC control, but the documented behavior also includes device inventory management and handling of sensitive data such as IP addresses, API keys, and passwords. That mismatch can cause users to disclose credentials and network-identifying information without clear informed consent, and it broadens the skill from control into persistent secret management.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description presents the capability as simple AC control, but the documented behavior also includes device inventory management and handling of sensitive data such as IP addresses, API keys, and passwords. That mismatch can cause users to disclose credentials and network-identifying information without clear informed consent, and it broadens the skill from control into persistent secret management.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states that configuration is stored in data/devices.json and the documented fields include IP addresses, location identifiers, API keys, and passwords, but the user-facing description does not clearly warn that this sensitive configuration persists across sessions. Persisting secrets and network metadata without explicit disclosure increases privacy risk and can expose home network details or device credentials if the storage is later accessed by other components or users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file performs persistent file writes to devices.json and is also used by methods that remove device records, but the code provides no confirmation prompt and no user-facing disclosure beyond internal error logging. For code files, safety-relevant data modification operations should have some visible warning, comment, or documented disclosure unless clearly covered elsewhere.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill exposes additional actuator functionality beyond the stated description by allowing powerful, econo, streamer, and holiday mode changes. Scope drift in a control skill is dangerous because policy, user-consent, and downstream agent routing may rely on the manifest text; an agent or user expecting only basic HVAC controls could unintentionally trigger higher-impact or privacy/energy-relevant behaviors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code removes a configured device via config.removeDevice(...), which is a destructive operation affecting saved user configuration. The function provides only a success message after deletion and includes no prior confirmation prompt, warning comment, or other disclosure in this file that the action is irreversible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This tool performs local network discovery and returns sensitive network identifiers including private IP addresses and MAC addresses. In an agent context, that can disclose internal topology and device identity information to users or downstream systems without any explicit consent, warning, or minimization, which increases privacy and reconnaissance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README explicitly promotes automatic device discovery by scanning the local network via UDP broadcast, but it does not warn users that invoking discovery performs active network probing. In a smart-home skill this is expected functionality, but the lack of disclosure can still create privacy and policy concerns, especially in managed or sensitive networks where unsolicited scanning may be unexpected or disallowed.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The runtime dependency daikin-ts is specified with a caret range, which allows newer compatible releases to be installed without explicit review. This increases supply-chain risk because a compromised or breaking upstream release could be pulled into the skill and affect production behavior.

Content

Scanner excerpt · package.json (reported line 25)May include surrounding context.

json
"author": "",
  "license": "GPL-3.0",
  "dependencies": {
    "daikin-ts": "^1.0.0"
  },
  "devDependencies": {
    "@types/node": "^20.10.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 28)May include surrounding context.

json
"daikin-ts": "^1.0.0"
  },
  "devDependencies": {
    "@types/node": "^20.10.0",
    "typescript": "^5.3.0",
    "vitest": "^1.0.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 29)May include surrounding context.

json
},
  "devDependencies": {
    "@types/node": "^20.10.0",
    "typescript": "^5.3.0",
    "vitest": "^1.0.0"
  },
  "openclaw": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
78% confidence
Finding

vitest is unpinned and has known advisories in some versions, so allowing a floating compatible version increases the chance of pulling in a vulnerable release during development or CI. Although it is a dev dependency, compromise here can still affect the build/test environment and potentially the software supply chain.

Content

Scanner excerpt · package.json (reported line 30)May include surrounding context.

json
"devDependencies": {
    "@types/node": "^20.10.0",
    "typescript": "^5.3.0",
    "vitest": "^1.0.0"
  },
  "openclaw": {
    "skill": {

Unverifiable Dependency: vitest has 3 known advisory(ies) (CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock); CVE-2025-24964 (Vitest allows Remote Code Execution when accessing a malicious website while Vit)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
80% confidence
Finding

The manifest includes vitest without an exact version, and the analyzer notes multiple known advisories affecting some Vitest releases. Because the actual installed version cannot be verified from this file, there is credible supply-chain and development-environment risk if an affected version is resolved.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code constructs a device connection using optional key/password credentials and then performs network communication via DaikinFactory(...) and device.updateStatus(). There is no confirmation prompt, logging, comment, or docstring in this file disclosing that the skill connects to a device over the network and may use supplied credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code binds a UDP socket, enables broadcast, and sends discovery messages across local network broadcast addresses. While this appears to be the skill's intended function, the file contains no confirmation prompt, user-facing log, or explanatory comment/docstring warning that local network traffic will be generated.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.