Back to skill

Security audit

Hive Home

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Hive Home purpose, but it handles sensitive smart-home credentials and includes an authentication example that prints reusable login material, so it needs user review before installation.

Review this before installing if you plan to grant real Hive credentials. Run first-time authentication only in a private local terminal, avoid emitting device credentials into agent-visible output, store secrets through your agent or OS secret mechanism, and consider pinning a reviewed pyhiveapi version. Use the skill only for Hive accounts and devices you control, since commands can change heating and hot-water state.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:89
Finding

Reusable Device Credentials Are Printed in Plaintext

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 89–92
Vulnerability Type: Plaintext exposure of reusable authentication credentials
Risk Level: Medium

Vulnerable Code:

python
# Save these for next time (e.g. to env or a secure store)
device_data = session.auth.getDeviceData()
print("Store for device login:", device_data)

Technical Analysis

The documented first-time authentication example retrieves reusable Hive device credentials and prints the complete credential object to standard output. These credentials allow subsequent device login without repeating SMS-based two-factor authentication.

Printing secrets creates multiple exposure channels, including terminal history or recording, agent tool output, CI/CD logs, remote session capture, support transcripts, and other systems that collect process output. This behavior also conflicts with the project's stated policy that credentials must not be placed in prompts or logs.

Attack Path

  1. A user or agent follows the first-time login example in SKILL.md.
  2. After successful password and SMS authentication, getDeviceData() returns reusable device authentication data.
  3. The script prints the credential object to standard output.
  4. The output is retained in an agent transcript, terminal recording, CI log, or another observable output channel.
  5. An attacker with access to that output extracts the device group key, device key, and device password.
  6. The attacker uses the exposed data with the Hive username and password, if also available, to perform device login without another SMS challenge.
  7. The resulting session can query or control devices associated with the Hive account.

Impact Assessment

Successful exploitation may weaken the protection provided by SMS two-factor authentication and expose persistent authentication material. In combination with the account credentials required by the documented device-login fl ...[truncated 385 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the print() statement and never emit the credential object through standard output or standard error.
  • Store each returned credential directly through an approved secret-store API with restrictive access controls.
  • If automatic secret storage is unavailable, require the enrollment process to run in a private local TTY and provide an explicit warning before revealing any value.
  • Display only redacted identifiers when diagnostic output is necessary.
  • Ensure agent tool output, application logs, exception traces, and telemetry cannot serialize the credential object.
  • Document credential revocation or device-registration rotation procedures for users who have already executed the example.
  • Add automated checks that detect printing or logging of values returned by getDeviceData().

T08 · Insecure Dependencies

Warning
Location
SKILL.md:65
Finding

Security-Sensitive Dependency Is Installed Without an Exact Version or Integrity Pin

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 65; also documented in README.md, lines 16, 26, and 32, and scripts/hive_control.py, lines 12–13
Vulnerability Type: Unpinned third-party dependency and unrestricted upgrade guidance
Risk Level: Medium

Vulnerable Instructions:

markdown
- **Python 3** with **pyhiveapi>=1.0.0** (session API): `pip install "pyhiveapi>=1.0.0"`. If you see attribute or method errors, run `pip install -U pyhiveapi` and try again.

Corresponding script documentation:

python
Requires: pyhiveapi>=1.0.0 (pip install "pyhiveapi>=1.0.0"); env HIVE_USERNAME, HIVE_PASSWORD (and device keys for non-interactive use).
If you see attribute/method errors, upgrade: pip install -U pyhiveapi

Technical Analysis

The installation requirement accepts any current or future pyhiveapi release greater than or equal to version 1.0.0. The troubleshooting guidance further recommends an unrestricted upgrade to the latest package release.

This dependency operates inside the same Python process as the skill and receives the Hive username, password, reusable device credentials, session tokens, device identifiers, and control commands. Python package code also executes during import, so a compromised, malicious, or unexpectedly changed future release would run with the privileges of the invoking user and have direct access to all process environment variables.

The audit found no evidence that the currently referenced package is malicious. The risk arises because the project does not identify a reviewed immutable version or verify package integrity, leaving future installations dependent on mutable package-index state.

Attack Path

  1. A user follows the documented pip install "pyhiveapi>=1.0.0" or pip install -U pyhiveapi instruction.
  2. Package resolution selects a future release that was not reviewed with this skill.
  3. A malicious maintainer release ...[truncated 1135 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the open-ended version range with an exact, reviewed version.
  • Maintain dependencies in a lock file or constraints file and include cryptographic hashes.
  • Install with hash verification, such as pip install --require-hashes -r requirements.txt.
  • Remove the recommendation to use unrestricted pip install -U; require deliberate dependency review and testing before upgrades.
  • Use a dedicated virtual environment with only the minimum dependencies needed by the skill.
  • Run the skill under a restricted operating-system account and inject only the environment variables it requires.
  • Add automated dependency vulnerability and provenance scanning to the release process.
  • Review upstream release notes and source changes before updating the pinned package and hashes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code clearly matches part of the description: it uses Hive credentials, connects to Hive endpoints through Pyhiveapi, and supports querying and controlling Hive heating and hot water. However, the declared description is broader, claiming support for lights and devices generally. In the supplied code, only 'climate' and 'water_heater' device types are accessed, and all commands operate exclusively on heating and hot water. There is no implementation for lights, plugs, or other Hive device categories. This is a description-behavior mismatch because the declared purpose materially overstates the supported device capabilities.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill requires sensitive environment variables for Hive credentials and device keys, but it does not declare an explicit tool scope such as permissions or allowed-tools. That omission weakens least-privilege controls and makes it harder for a host agent to constrain or audit secret access before the skill is invoked.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
- **OpenClaw:** Set in `~/.openclaw/openclaw.json` under `skills.entries.hivehome.env`. OpenClaw injects these into the process for the agent run; they are not put in prompts or logs.
- **Other agents:** Use that agent’s recommended way to inject env vars or secrets so the skill’s scripts see them at runtime.

**Agent instruction:** If credentials are missing, do not ask the user to paste passwords or keys in chat. Tell them to set the required environment variables (or configure the skill in their agent’s config) and run the script again. See [references/CREDENTIALS.md](references/CREDENTIALS.md) for platform-specific notes.

## When to use this skill

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/REFERENCE.md (reported line 84)May include surrounding context.

md
## Backend and history

- **Base URL:** The app uses endpoints such as `https://beekeeper.hivehome.com/` and `https://api.prod.bgchprod.info/`; Pyhiveapi encapsulates these.
- **Original reverse-engineering:** [James Kirby – Hive Home REST API](https://jedkirby.com/blog/hive-home-rest-api) (simple login no longer works; 2FA is required).
- **Sniffing the app:** To discover new endpoints, use browser DevTools on [my.hivehome.com](https://my.hivehome.com) (Network tab) or mitmproxy for the mobile app. Prefer the web app first.

Static analysis

No suspicious patterns detected.