Back to skill

Security audit

Tesla

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Tesla control skill, but it can control a real vehicle and reveal its location, so users should use it only with explicit intent.

Before installing, understand that this skill can unlock a real car, change climate and charging, sound the horn, flash lights, wake the vehicle, and reveal precise location. Use it only in trusted sessions, confirm state-changing commands explicitly, protect ~/.tesla_cache.json, avoid sharing location output, and prefer pinning/reviewing the teslapy dependency.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/tesla.py:3
Finding

Unbounded Third-Party Dependency Can Introduce Unreviewed Code

Content
View full analysis

Vulnerability Details

File Location: scripts/tesla.py:3-6
Vulnerability Type: Unbounded third-party dependency
Risk Level: Medium

Vulnerable Code:

python
# /// script
# requires-python = ">=3.10"
# dependencies = [
#     "teslapy>=2.0.0",
# ]

Technical Analysis

The PEP 723 dependency declaration permits any current or future teslapy release from version 2.0.0 onward. The project provides no exact version pin, dependency lockfile, package hash, or other integrity constraint. Consequently, a compatible release published after this audit may be downloaded and executed without its code having been reviewed.

The package is imported at runtime and handles Tesla OAuth authentication, token caching, network communication, vehicle information, and physical vehicle commands. Python package initialization code executes during import, so a compromised dependency release could run arbitrary code with the privileges of the user invoking the Skill.

The direct tesla.fetch_token() call at scripts/tesla.py:35 is consistent with the declared OAuth authentication workflow and is not, by itself, evidence of malicious exfiltration. However, the network and token-handling implementation resides in the external dependency and was not included in the audited project.

Attack Path

  1. An attacker compromises the upstream teslapy project, its maintainer account, or the package publication process.
  2. The attacker publishes a malicious release whose version satisfies teslapy>=2.0.0.
  3. A PEP 723-compatible runner resolves and installs that release when the Skill is executed.
  4. scripts/tesla.py imports teslapy, causing attacker-controlled package initialization code to execute.
  5. The malicious code runs with the invoking user's local permissions and may read ~/.tesla_cache.json, capture OAuth data, contact attacker-controlled infrastructure, or invoke Tesla account and vehicle operations. 6 ...[truncated 1033 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the open-ended version range with an exact, reviewed version, for example:

    python
    # dependencies = [
    #     "teslapy==2.0.0",
    # ]
    

    Select the exact version only after verifying its source and release provenance.

  2. Use a reproducible dependency lock mechanism with cryptographic hashes. Require package hash verification during installation so a substituted artifact is rejected.

  3. Restrict dependency resolution to an explicitly trusted package index and disable unintended fallback indexes to reduce dependency-confusion exposure.

  4. Review dependency updates before changing the pinned version, including package ownership, release history, source changes, transitive dependencies, and published artifact integrity.

  5. Run the Skill with a dedicated, least-privileged operating-system account or sandbox. Restrict filesystem access to the required token cache and limit network access to documented Tesla authentication and API endpoints where operationally feasible.

  6. Protect ~/.tesla_cache.json with owner-only permissions and document immediate Tesla token revocation procedures for suspected compromise.

  7. Consider isolating authentication from routine vehicle commands so the long-lived refresh token is not unnecessarily exposed to every execution context.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documentation understates or misstates the skill's operational behavior by omitting disruptive real-world actions such as honk, flash, wake, and token caching/auth management, while also inconsistently describing the API used. For a vehicle-control skill, incomplete disclosure can cause users or orchestration agents to invoke commands without appreciating that they trigger physical actions or create persistent credential artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README promotes remote actions such as unlock, climate control, charging, horn, and precise location access without warning users about security, safety, privacy, or accidental-trigger risks. In a skill that enables real-world vehicle control, missing cautions can lead users to authorize powerful actions without understanding the consequences of misuse, prompt injection, or mistaken activation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares access to environment variables via metadata but does not define an explicit tool scope such as permissions or allowed-tools. In a skill that can issue real-world vehicle commands and handle authentication state, this weakens least-privilege controls and makes it harder for a host system or reviewer to understand what resources the skill may access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill exposes commands that can lock/unlock doors, start/stop climate, start/stop charging, honk, flash lights, and wake a vehicle, but the documentation does not prominently warn that these are real-world actions that may execute immediately. In the context of connected vehicle control, missing confirmation guidance materially raises the risk of accidental or socially engineered physical actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented location command reveals precise vehicle location without any privacy warning or handling guidance. Because vehicle location is sensitive personal data, omission of a warning increases the risk that users or downstream agents expose or request this information without understanding its privacy implications.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code exposes remote honk and flash capabilities, but the skill metadata only describes lock/unlock, climate, location, and charge features. This mismatch can undermine user consent and policy review because an agent may gain unexpected actuation abilities over a physical vehicle that were not clearly disclosed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation claims use of the unofficial Owner API while earlier text says the Fleet API/VCP flow is used automatically. This inconsistency can mislead users and reviewers about authentication, protocol, and security properties, increasing the chance of unsafe deployment or incorrect trust assumptions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file docstring says the script provides Tesla control via an 'unofficial API,' but the manifest says it supports the Tesla Fleet API. These statements describe different intended integrations and could mislead users or reviewers about what backend and trust model the skill actually uses.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.