Back to skill

Security audit

AC-Nexus

Security checks for vulnerabilities and agentic risk

Overview

AC-Nexus is a disclosed smart air-conditioner automation skill whose device control, stored configuration, and background scheduling fit its stated purpose.

Before installing, review the upstream GitHub repository and Python dependencies because the skill directs agents to run external code. Use it only with devices and accounts you control, and confirm before enabling schedules, auto-adjust, storm shutdown, or storing Xiaomi/local device tokens in persistent config.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.