Local Tuya Light Control

PassAudited by VirusTotal on Apr 16, 2026.

Findings (1)

The skill bundle contains instructions for an AI agent to execute local binaries (lampctl.exe) and Python scripts (lamp_control.py) using hardcoded, user-specific paths (e.g., C:\Users\1111\...). It also includes a meta-instruction for the agent to modify its own SKILL.md file if the project path differs, which is a risky behavior that could be exploited via prompt injection. While the stated goal of controlling Tuya lights is plausible, the reliance on unverified local binaries and the instruction for self-modification of the skill's logic are significant security concerns.