Back to skill

Security audit

Wyze

Security checks across malware telemetry and agentic risk

Overview

This skill clearly does what it claims: it lets an assistant control Wyze lights, plugs, and switches, with disclosed local credential and token handling.

Install only if you are comfortable giving the assistant control over your Wyze lights, plugs, and switches. Store the Wyze secrets and token directory somewhere private, and be especially careful with commands using 'all' or devices connected to doors, gates, garage openers, or important equipment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The script creates and uses a token directory and later tells the user that the Wyze token is cached there, but it does not present a clear warning before enabling persistent credential storage or verify restrictive file permissions. Cached smart-home auth tokens on disk can be abused by any local user, malware, or other process with filesystem access to control devices without re-entering credentials.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
These functions directly issue power-changing commands to physical devices, and later command handlers allow bulk targeting including "all" without any confirmation step. In a smart-home context, unintended or coerced execution can materially affect the physical environment, causing safety, privacy, or operational issues such as lights switching unexpectedly or power being cut to connected equipment.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.