Back to skill

Security audit

My Tesla

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Tesla-control CLI with real account and vehicle access, but I found no hidden exfiltration, deception, or automatic unsafe behavior in the artifacts.

Install only if you are comfortable giving this skill Tesla account access capable of reading vehicle data and issuing remote commands. Treat ~/.tesla_cache.json and ~/.my_tesla/mileage.sqlite as sensitive, avoid storing them in shared or synced locations, review permissions, and enable the hourly launchd example only if you intentionally want ongoing local mileage logging.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tesla.py:83
Finding

OAuth Token Cache Permissions Are Applied Only After Sensitive Data Is Written

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tesla.py:1788
Finding

Mileage Telemetry Database and WAL Files Are Created Without Explicit Private Permissions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/tesla.py:2
Finding

Security-Sensitive Tesla API Dependency Uses an Unbounded Version Range

Content
View full analysis
=3.10" # dependencies = [ # "teslapy>=2.0.0", # ] # /// ``` ### Technical Analysis The Skill delegates OAuth processing, token-cache management, Tesla API communication, and vehicle command transmission to `teslapy`. The dependency declaration accepts every future version at or above `2.0.0`, and the project does not provide an audited lockfile or package hash. This is not evidence that the currently available `teslapy` package is malicious. The weakness is that future installations are not reproducible and may automatically resolve to a newly released, compromised, or incompatible version with access to OAuth credentials and vehicle operations. ### Attack Path 1. A user installs or runs the script through tooling that resolves its inline dependency metadata. 2. The resolver selects the newest package version satisfying `teslapy>=2.0.0`. 3. A future release is compromised at the package source, maintainer account, build pipeline, or distribution layer. 4. The compromised package executes when imported by `get_tesla()`. 5. It gains the same local privileges as the Skill process and can access the supplied account email, authentication callback, token cache, and Tesla API session. 6. Malicious dependency code can copy credentials, alter API requests, expose vehicle data, or send unauthorized commands. ### Impact Assessment A compromised dependency would execute with the user's local privileges and operate inside the authentication and vehicle-control trust boundary. Potential impact includes token theft, disclosure of vehicle data and location, arbitrary remote vehicle commands within the authorized API scope, and access to files available to the invoking user. The likelihood is lower because exploitation dep ...[truncated 141 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about a Tesla control skill with vehicle status and remote command capabilities. The supplied code chunk does not implement any Tesla-related functionality, authentication, API calls, vehicle actions, confirmation gates, or chat-oriented status output. Instead, it is purely a test runner and repository cleanup script for Python bytecode artifacts. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is about a functional Tesla-control skill with Tesla Owner API integration and vehicle operations. The supplied code chunk does none of that; it only configures Python test behavior to avoid creating pycache files. This is a materially different purpose and unrelated supporting code on its own, so the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The supplied code does not implement or exercise Tesla Owner API vehicle control features such as authentication, vehicle listing, status retrieval, lock/unlock, climate, charging, or location commands. Instead, it focuses on local database tests for mileage tracking utilities. While mileage logging could be a possible auxiliary feature in a broader Tesla tool, this specific chunk’s primary purpose is unrelated unit testing of local persistence behavior, which is not represented in the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code does not implement or exercise Tesla Owner API vehicle control features such as authentication, status retrieval, lock/unlock, climate, charging, or location commands. Instead, it creates an in-memory SQLite database and runs unit tests for mileage export filtering helpers. While this may belong to a broader Tesla-related project, the behavior in this chunk is materially different from the declared purpose of a macOS Tesla control skill. Therefore this chunk is mismatched with the declared description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The changelog documents a local SQLite-based mileage tracking and export feature that is not reflected in the higher-level skill description, expanding the data collection surface beyond simple remote vehicle control/status. Undeclared persistent telemetry storage can surprise users, increase privacy risk, and create retention/export paths for sensitive vehicle history without clear consent or disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Persistent telemetry/history collection is a material capability increase compared with the stated purpose of checking current car state and running remote commands. Even if implemented locally, longitudinal odometer records can reveal usage patterns and travel behavior, making the mismatch between stated purpose and actual behavior a privacy/security concern.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · CHANGELOG.md (reported line 182)May include surrounding context.

md
- Make `location` safer by default: show approximate (rounded) coordinates unless `--yes` is provided for precise.

## 0.1.11 — 2026-01-28
- Remove `--yes` safety gate from `location` (prints coordinates + maps link without confirmation).

## 0.1.10 — 2026-01-28
- Refactor: centralize missing-email handling into a single helper with a clearer example.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Removing the confirmation gate for precise location output makes sensitive geolocation easier to expose accidentally through normal chat/CLI use, logs, screenshots, or downstream automation. In a Tesla-control skill, exact coordinates directly reveal where a user's vehicle is, which is especially sensitive and can create stalking, theft, or personal safety risks.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 191)May include surrounding context.

text

### Run every hour (macOS launchd example)
Create `~/Library/LaunchAgents/com.mytesla.mileage.plist`:
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 191)May include surrounding context.

text

### Run every hour (macOS launchd example)
Create `~/Library/LaunchAgents/com.mytesla.mileage.plist`:
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 194)May include surrounding context.

text

### Run every hour (macOS launchd example)
Create `~/Library/LaunchAgents/com.mytesla.mileage.plist`:
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 195)May include surrounding context.

text

### Run every hour (macOS launchd example)
Create `~/Library/LaunchAgents/com.mytesla.mileage.plist`:
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 216)May include surrounding context.

text

### Run every hour (macOS launchd example)
Create `~/Library/LaunchAgents/com.mytesla.mileage.plist`:
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 220)May include surrounding context.

text

### Run every hour (macOS launchd example)
Create `~/Library/LaunchAgents/com.mytesla.mileage.plist`:
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 194)May include surrounding context.

Create ~/Library/LaunchAgents/com.mytesla.mileage.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
  <dict>
    <key>Label</key><string>com.mytesla.mileage</string>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 220)May include surrounding context.

text
Load it:
```bash
launchctl load -w ~/Library/LaunchAgents/com.mytesla.mileage.plist

Tests

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool restrictions even though it clearly relies on sensitive capabilities including shell execution, environment-variable access, and local file reads/writes. In an agent setting, missing scope boundaries increases the chance the skill can be invoked with broader-than-necessary privileges or reused in unintended ways, especially because it handles auth tokens and can issue real-world vehicle commands.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill persists Tesla OAuth session material to a fixed cache file in the user's home directory, creating durable local access to the Tesla account beyond a single run. Although the code attempts to chmod the cache to 0600, persistent token storage still increases the blast radius of local compromise, backup leakage, or accidental file sharing because an attacker with local access may reuse the cached session.

Content

Scanner excerpt · scripts/tesla.py (reported line 23)May include surrounding context.

python
from datetime import datetime, timezone
from pathlib import Path

# Keep the repo clean: don't write __pycache__/ bytecode files when running the CLI.
# (Also helps keep private repos from accumulating noisy artifacts.)
sys.dont_write_bytecode = True

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The lock command sends a live LOCK command to the vehicle, which is a safety-relevant remote operation, but unlike other mutating commands in this file it does not call require_yes. While it does print after execution, there is no pre-action confirmation or stronger user disclosure at the action point.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill implements persistent local mileage tracking in a SQLite database, but the declared skill description emphasizes vehicle control and local auth caching rather than ongoing telemetry storage. This creates a transparency and consent gap: users may authorize the skill for remote control without realizing it can build a historical local log of odometer and vehicle state metadata.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill's stated purpose is Tesla vehicle control through local auth caching and interactive/API use, but it also sources account identity from TESLA_EMAIL and other behavior flags from environment variables. While convenient, ambient environment-variable intake is not stated in the manifest and is not strictly required for the Tesla-control purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The wake command performs a remote action against the vehicle by calling sync_wake_up(), but it does not require --yes or present any explicit warning before doing so. Other disruptive actions in the script are generally protected by require_yes, so this is an inconsistent lack of disclosure for a live remote operation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.