Back to skill

Security audit

Govee

Security checks across malware telemetry and agentic risk

Overview

The skill is for Govee device management, but its description and safety labels understate that it can change device state.

Review this skill before installing if you want read-only Govee access. It can operate connected Govee devices, and because the write action is not clearly tagged, users should require explicit confirmation before any device-control command is run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The manifest and description frame the skill as suitable for 'searching and reading data,' but the skill exposes a state-changing `control_capability` action. That mismatch can cause a calling agent or user to invoke the skill under the assumption it is read-only, increasing the chance of unintended device changes such as powering devices on/off or altering brightness, color, or temperature.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger guidance says to use this skill for 'ANY Govee request,' which is overly broad and may cause automatic invocation whenever Govee is merely mentioned, even if the user did not ask to operate devices. In a skill that includes write functionality, broad routing increases the risk of inappropriate tool selection and accidental state-changing actions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.