Back to skill

Security audit

Google Home/Nest

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a Google Nest control guide, but it includes unsafe global CLI installation instructions and weak handling of smart-home tokens and camera access.

Review this carefully before installing. Do not run the global ln -sf command as written, and do not rely on any helper script that is not included in the package. Use a dedicated Google account or least-privilege project where possible, store tokens in a protected credential store or a 0600 file, and require explicit user confirmation before changing device state or accessing camera snapshots and streams.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
SKILL.md:97
Finding

Global Command Hijacking Through Forced External Symlink

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 97-103
Vulnerability Type: Tool hijacking through replacement of a globally accessible command
Risk Level: High

Vulnerable Code

bash
A `nest` CLI helper is included at `scripts/nest`:

# Make it available globally
ln -sf /Users/mitchellbernstein/clawd/skills/google-home/scripts/nest /usr/local/bin/nest

# List devices
nest list

Technical Analysis

The documentation instructs the user to force-create the global /usr/local/bin/nest symlink using a hard-coded source path outside the audited project. The -f option can replace an existing file or symlink at the destination.

The project contains only SKILL.md; the claimed scripts/nest helper is not included. Consequently, the executable installed under the legitimate-looking nest command cannot be audited as part of this package. If another party can create or modify the hard-coded source path, subsequent nest invocations will execute that party's code.

This creates a local tool-hijacking primitive and violates least-privilege principles by modifying a global executable directory when a project-local invocation would be sufficient.

Attack Path

  1. An attacker gains write access to, or pre-creates, /Users/mitchellbernstein/clawd/skills/google-home/scripts/nest.
  2. The attacker places a malicious executable at that location.
  3. The user follows the documentation and runs the forced symlink command, with elevated permissions if required by the system.
  4. /usr/local/bin/nest is created or an existing command at that path is replaced.
  5. The user or another process invokes nest, believing it to be the documented Google Home helper.
  6. The attacker's executable runs with the privileges and environment of the invoking user.

Impact Assessment

Successful exploitation permits arbitrary command execution with the privileges of any user who invokes the hijacked comm ...[truncated 313 chars]

Remediation
View remediation

Remediation Suggestions

  • Include the referenced helper inside the audited package rather than referring to an external, user-specific path.
  • Resolve the helper path relative to the skill directory and verify that the resolved file remains inside the package.
  • Do not use ln -sf against global executable directories.
  • Prefer direct project-local execution or installation into a user-controlled directory such as ~/.local/bin.
  • Before installation, check whether the destination already exists and require explicit user confirmation rather than replacing it.
  • Verify the helper's ownership, permissions, integrity, and expected checksum before installation or execution.
  • Clearly display any operation requiring elevated privileges and avoid requesting those privileges unless strictly necessary.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:118
Finding

OAuth Access Token Stored in Plaintext Without Permission Safeguards

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 118-126
Vulnerability Type: Insecure storage of sensitive authentication credentials
Risk Level: Medium

Vulnerable Code

markdown
Create `~/.config/google-home/config.json`:

```json
{
  "project_id": "your-google-cloud-project-id",
  "access_token": "your-oauth-access-token"
}
text

### Technical Analysis

The documentation directs users to store a bearer access token in a plaintext JSON file but does not require restrictive directory ownership or file permissions. The effective permissions of a newly created file depend on the user's umask and creation method. On an improperly configured or shared system, the file may become readable by other local accounts, backup processes, or unrelated applications.

OAuth bearer tokens generally authorize requests based solely on possession. A party that reads the token may therefore submit authenticated requests without knowing the user's password. Although access tokens expire, they remain sensitive throughout their validity period.

### Attack Path

1. The user creates `~/.config/google-home/config.json` as documented.
2. The user's umask or file-creation process results in permissions that allow an unauthorized local account or process to read the file.
3. The attacker reads and copies the OAuth access token.
4. The attacker sends requests to the Google Smart Device Management API using `Authorization: Bearer <stolen-token>`.
5. Until the token expires or is revoked, the attacker performs operations allowed by the token's scopes and the associated account permissions.

### Impact Assessment

Exploitation can expose information about linked Nest devices and permit unauthorized device operations within the token's granted scopes. Depending on those scopes and available devices, this may affect thermostats, cameras, doorbells, or other smart-home equipment. Camera-related access could also
...[truncated 156 chars]
Remediation
View remediation

Remediation Suggestions

  • Store OAuth tokens in an operating-system credential manager or secret service instead of a plaintext configuration file.
  • If file-based storage is unavoidable, create ~/.config/google-home with mode 0700 and the token file with mode 0600.
  • Validate file ownership and permissions before reading credentials, and refuse to use files accessible by other users.
  • Separate non-sensitive configuration, such as the project identifier, from sensitive token material.
  • Document token revocation and rotation procedures.
  • Request only the minimum OAuth scopes required for the intended device operations.
  • Avoid printing tokens in logs, command histories, diagnostic output, or error messages.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The skill instructs users to obtain and handle OAuth access-related secrets and shows token exchange commands in plaintext shell usage, creating a realistic risk of credential exposure through shell history, copied commands, logs, or insecure storage. Because these tokens authorize access to home devices and cameras, compromise could enable unauthorized monitoring or device control.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

  1. Get Access Token
    bash
    # Replace with your values
    curl -s \
    

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: google-home
description: Control Google Nest devices (thermostats, cameras, doorbells) via the Google Smart Device Management API using curl and jq.
metadata: {"clawdbot":{"emoji":"🏠","requires":{"bins":["curl","jq"]}}
---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly documents commands that can change the state of physical devices such as thermostats, fans, speakers, and playback, but it does not warn users that these actions will affect real household equipment. That omission increases the risk of accidental or socially engineered misuse, especially when an agent may execute commands on behalf of a user without clear confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation advertises camera snapshot and live stream capabilities without any privacy or consent warning. Because these operations expose sensitive in-home imagery, normalizing them without guardrails can enable covert surveillance or unintentional privacy violations.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The documented configuration stores an OAuth access token in a local JSON file under the user's home directory without any mention of file permissions, encryption, or secure storage. Persisting bearer tokens in plaintext increases the chance that other local users, malware, backups, or developer tooling can recover credentials and reuse them to access connected devices.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

Configuration

Create ~/.config/google-home/config.json:

json
{

Static analysis

No suspicious patterns detected.