Back to skill

Security audit

HomeKit Smart Home Control

Security checks across malware telemetry and agentic risk

Overview

This skill openly provides user-run HomeKit device control, with expected smart-home safety risks but no evidence of hidden or unrelated behavior.

Install only if you are comfortable letting this skill control your HomeKit accessories. Review each command before running it, be careful with unpairing and batch on/off actions, and protect the local pairing file because it can enable future control of paired devices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
88% confidence
Finding
This skill can control real-world smart home devices including lights, outlets, switches, and pairing actions, but the description does not warn that commands may immediately affect physical devices in the user's environment. In an agent setting, lack of a clear real-world effects warning can lead to unintended actuation, disruption, or unsafe automation if the user or downstream system invokes the skill without understanding its consequences.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.