T09 · Insecure Skill Coding Practices
- Location
scripts/tesla.py:83- Finding
OAuth Token Cache Permissions Are Applied Only After Sensitive Data Is Written
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed Tesla-control CLI with real account and vehicle access, but I found no hidden exfiltration, deception, or automatic unsafe behavior in the artifacts.
Install only if you are comfortable giving this skill Tesla account access capable of reading vehicle data and issuing remote commands. Treat ~/.tesla_cache.json and ~/.my_tesla/mileage.sqlite as sensitive, avoid storing them in shared or synced locations, review permissions, and enable the hourly launchd example only if you intentionally want ongoing local mileage logging.
scripts/tesla.py:83OAuth Token Cache Permissions Are Applied Only After Sensitive Data Is Written
scripts/tesla.py:1788Mileage Telemetry Database and WAL Files Are Created Without Explicit Private Permissions
scripts/tesla.py:2Security-Sensitive Tesla API Dependency Uses an Unbounded Version Range
The declared description is about a Tesla control skill with vehicle status and remote command capabilities. The supplied code chunk does not implement any Tesla-related functionality, authentication, API calls, vehicle actions, confirmation gates, or chat-oriented status output. Instead, it is purely a test runner and repository cleanup script for Python bytecode artifacts. This is a materially different primary purpose, so the description does not accurately represent the code.
The declared description is about a functional Tesla-control skill with Tesla Owner API integration and vehicle operations. The supplied code chunk does none of that; it only configures Python test behavior to avoid creating pycache files. This is a materially different purpose and unrelated supporting code on its own, so the description does not accurately represent what this code chunk actually does.
The supplied code does not implement or exercise Tesla Owner API vehicle control features such as authentication, vehicle listing, status retrieval, lock/unlock, climate, charging, or location commands. Instead, it focuses on local database tests for mileage tracking utilities. While mileage logging could be a possible auxiliary feature in a broader Tesla tool, this specific chunk’s primary purpose is unrelated unit testing of local persistence behavior, which is not represented in the declared description.
The supplied code does not implement or exercise Tesla Owner API vehicle control features such as authentication, status retrieval, lock/unlock, climate, charging, or location commands. Instead, it creates an in-memory SQLite database and runs unit tests for mileage export filtering helpers. While this may belong to a broader Tesla-related project, the behavior in this chunk is materially different from the declared purpose of a macOS Tesla control skill. Therefore this chunk is mismatched with the declared description.
The changelog documents a local SQLite-based mileage tracking and export feature that is not reflected in the higher-level skill description, expanding the data collection surface beyond simple remote vehicle control/status. Undeclared persistent telemetry storage can surprise users, increase privacy risk, and create retention/export paths for sensitive vehicle history without clear consent or disclosure.
Persistent telemetry/history collection is a material capability increase compared with the stated purpose of checking current car state and running remote commands. Even if implemented locally, longitudinal odometer records can reveal usage patterns and travel behavior, making the mismatch between stated purpose and actual behavior a privacy/security concern.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- Make `location` safer by default: show approximate (rounded) coordinates unless `--yes` is provided for precise.
## 0.1.11 — 2026-01-28
- Remove `--yes` safety gate from `location` (prints coordinates + maps link without confirmation).
## 0.1.10 — 2026-01-28
- Refactor: centralize missing-email handling into a single helper with a clearer example.
Removing the confirmation gate for precise location output makes sensitive geolocation easier to expose accidentally through normal chat/CLI use, logs, screenshots, or downstream automation. In a Tesla-control skill, exact coordinates directly reveal where a user's vehicle is, which is especially sensitive and can create stalking, theft, or personal safety risks.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### Run every hour (macOS launchd example)
Create `~/Library/LaunchAgents/com.mytesla.mileage.plist`:
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### Run every hour (macOS launchd example)
Create `~/Library/LaunchAgents/com.mytesla.mileage.plist`:
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### Run every hour (macOS launchd example)
Create `~/Library/LaunchAgents/com.mytesla.mileage.plist`:
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### Run every hour (macOS launchd example)
Create `~/Library/LaunchAgents/com.mytesla.mileage.plist`:
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### Run every hour (macOS launchd example)
Create `~/Library/LaunchAgents/com.mytesla.mileage.plist`:
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### Run every hour (macOS launchd example)
Create `~/Library/LaunchAgents/com.mytesla.mileage.plist`:
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Create ~/Library/LaunchAgents/com.mytesla.mileage.plist:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>Label</key><string>com.mytesla.mileage</string>
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Load it:
```bash
launchctl load -w ~/Library/LaunchAgents/com.mytesla.mileage.plist
The skill declares no explicit tool restrictions even though it clearly relies on sensitive capabilities including shell execution, environment-variable access, and local file reads/writes. In an agent setting, missing scope boundaries increases the chance the skill can be invoked with broader-than-necessary privileges or reused in unintended ways, especially because it handles auth tokens and can issue real-world vehicle commands.
The skill persists Tesla OAuth session material to a fixed cache file in the user's home directory, creating durable local access to the Tesla account beyond a single run. Although the code attempts to chmod the cache to 0600, persistent token storage still increases the blast radius of local compromise, backup leakage, or accidental file sharing because an attacker with local access may reuse the cached session.
from datetime import datetime, timezone
from pathlib import Path
# Keep the repo clean: don't write __pycache__/ bytecode files when running the CLI.
# (Also helps keep private repos from accumulating noisy artifacts.)
sys.dont_write_bytecode = True
The lock command sends a live LOCK command to the vehicle, which is a safety-relevant remote operation, but unlike other mutating commands in this file it does not call require_yes. While it does print after execution, there is no pre-action confirmation or stronger user disclosure at the action point.
The skill implements persistent local mileage tracking in a SQLite database, but the declared skill description emphasizes vehicle control and local auth caching rather than ongoing telemetry storage. This creates a transparency and consent gap: users may authorize the skill for remote control without realizing it can build a historical local log of odometer and vehicle state metadata.
The skill's stated purpose is Tesla vehicle control through local auth caching and interactive/API use, but it also sources account identity from TESLA_EMAIL and other behavior flags from environment variables. While convenient, ambient environment-variable intake is not stated in the manifest and is not strictly required for the Tesla-control purpose.
The wake command performs a remote action against the vehicle by calling sync_wake_up(), but it does not require --yes or present any explicit warning before doing so. Other disruptive actions in the script are generally protected by require_yes, so this is an inconsistent lack of disclosure for a live remote operation.
No suspicious patterns detected.