Back to skill

Security audit

Geeklink Home

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do what it advertises, but it can control home devices and handles gateway tokens in ways users should review carefully.

Install only if you are comfortable giving this skill access to your Geeklink gateway and home-device controls. Treat the pairing token as a secret, avoid putting it in shell history or Markdown files, prefer a tightly scoped local gateway address, and review or harden the config file where tokens are stored.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
vendor/geeklink-lan-cli.js:3470
Finding

Gateway Credentials May Be Sent over Plaintext HTTP to an Unrestricted Destination

Content
View full analysis
controller.abort(), timeoutMs); try { const response = await fetch(`${this.baseUrl}${API_BASE}${path}`, { method, headers, body: body !== void 0 ? JSON.stringify(body) : void 0, signal: controller.signal }); ``` ### Technical Analysis The gateway host is supplied through configuration or command-line input. If the host has no scheme, the code automatically prefixes it with `http://`. Explicit HTTP and HTTPS URLs are both accepted, and there is no check that the destination is a private, link-local, or otherwise approved LAN address. During authenticat ...[truncated 1957 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
vendor/geeklink-lan-cli.js:3635
Finding

Reusable Pairing and Session Tokens Are Persisted in Plaintext without Explicit Access Restrictions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:35
Finding

Setup Instructions Encourage Exposure of the Pairing Token through Process Arguments and Plaintext Documentation

Content
View full analysis
--pairing-token ` once to cache session. ``` The same command is repeated in the localized setup section: ```bash node scripts/geeklink-home.js login --host --pairing-token ``` The supplied gateway template also provides a location for recording the credential: ```md # Geeklink Home Gateway Template Get these values from the gateway details page in the Geeklink app under `AI Skill Access`. | Name | Host | Pairing Token | Notes | | :--- | :--- | :--- | :--- | | Home Gateway | 192.168.1.50:80 | token_here | Main house gateway | ``` ### Technical Analysis The recommended login workflow places the pairing token directly in a command-line argument. Depending on the host environment, command-line secrets may be exposed through: - Shell history - Process inspection interfaces - Terminal recording - Debug and audit logs - Agent conversation or tool-call transcripts - Crash reports or support bundles The Markdown template separately encourages users to record a live pairing token in a plaintext document. Such files are easy to copy into repositories, synchronize through cloud storage, attach to support requests, or include in backups. This finding concerns the documented workflow rather than covert credential collection by the Skill. ### Attack Path 1. The user follows the documented command and substitutes the real pairing token. 2. The command is retained in shell history, terminal logs, an Agent transcript, or process metadata. 3. Alternatively, the user stores the token ...[truncated 624 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
vendor/geeklink-lan-cli.js:3669
Finding

Logout Preserves the Pairing Token and Therefore Does Not Remove Local Authentication Capability

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (31)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
- Packaged around the bundled `vendor/geeklink-lan-cli.js` runtime

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
- Packaged around the bundled `vendor/geeklink-lan-cli.js` runtime

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
- Packaged around the bundled `vendor/geeklink-lan-cli.js` runtime

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
- Packaged around the bundled `vendor/geeklink-lan-cli.js` runtime

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
3. Run `node scripts/geeklink-home.js login --host <host> --pairing-token <token>` once to cache session.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · vendor/geeklink-lan-cli.js (reported line 2634)May include surrounding context.

js
* Parse options from `argv` removing known options,
       * and return argv split into operands and unknown arguments.
       *
       * Side effects: modifies command by storing options. Does not reset state if called again.
       *
       * Examples:
       *

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill explicitly documents LAN access to a home automation gateway and physical device control, but it declares no tool scope or permissions boundary. In a skill runtime, that omission weakens user and platform visibility into the fact that the skill can perform network operations against local infrastructure and change real-world device state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation describes scene activation and device control but does not warn that these actions can alter physical home device state or trigger chained automations. That omission increases the risk of unsafe or unintended actions by users or agents, especially in a home environment where scenes may affect locks, alarms, HVAC, or power-consuming devices.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup instructions tell users to retrieve and use a pairing token but do not identify it as a sensitive credential. If that token is exposed in logs, transcripts, screenshots, or prompts, an attacker with LAN reach could potentially authenticate to the gateway and control or observe home devices.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · vendor/geeklink-lan-cli.js (reported line 321)May include surrounding context.

js
*/
      subcommandTerm(cmd) {
        const args = cmd.registeredArguments.map((arg) => humanReadableArgName(arg)).join(" ");
        return cmd._name + (cmd._aliases[0] ? "|" + cmd._aliases[0] : "") + (cmd.options.length ? " [options]" : "") + // simplistic check for non-help option
        (args ? " " + args : "");
      }
      /**

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · vendor/geeklink-lan-cli.js (reported line 3572)May include surrounding context.

js
(waitSec + 10) * 1e3
    );
  }
  async requestJson(method, path, body, withAuth = false, timeoutMs = 15e3) {
    const headers = {
      Accept: "application/json"
    };

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill writes pairing and session tokens to a predictable config file under the user's home directory without any evident file-permission hardening, encryption, or prominent disclosure. These tokens are bearer-style credentials for local gateway control, so local compromise, accidental backup/sync leakage, or multi-user host exposure could let another process or user control devices and scenes.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/geeklink-home.js:16

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
vendor/geeklink-lan-cli.js:1820