Back to skill

Security audit

BroadlinkAC For Agent

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent AC-control purpose, but it asks users to install unpinned remote code and sets up persistent device automation with stored API keys.

Review this carefully before installing. Prefer a pinned commit or signed release, inspect the cloned repository and requirements, and run it in a constrained environment. Use low-scope weather API keys, protect or avoid persisting credentials, verify any QWeather host, and only enable schedules or auto-adjust after confirming you want the AC to keep changing state without the agent present.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:22
Finding

Mutable Remote Code and Dependencies Are Retrieved and Installed Without Integrity Pinning

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:22-24
Vulnerability Type: Remote payload retrieval and insecure software supply chain
Risk Level: High

Vulnerable snippet:

bash
git clone https://github.com/oywq00008-cell/BroadlinkAC-For-Agent.git
cd BroadlinkAC-For-Agent
pip install -r requirements-core.txt

Technical Analysis

The packaged project contains only SKILL.md; the executable implementation and its dependency manifest are not included in the reviewed artifact. Instead, the instructions retrieve a mutable Git repository and install packages from its externally maintained requirements-core.txt.

The clone command does not pin a commit hash or authenticated release artifact. The dependency installation also does not demonstrate exact version locking, package hashes, signature verification, or restrictions on package indexes. Consequently, the code ultimately executed can differ from the content that was available when this Skill was audited.

This behavior exceeds what can be safely reviewed within the supplied artifact. While obtaining an AC-control implementation may be necessary for the declared functionality, retrieving mutable code at runtime without integrity controls is not the minimum safe privilege or trust model.

Attack Path

  1. An attacker compromises the referenced GitHub account, repository, release process, or an upstream dependency source.
  2. The attacker modifies repository code or requirements-core.txt, or publishes a malicious package version accepted by that manifest.
  3. An agent follows the documented Quick Start instructions.
  4. git clone retrieves the modified payload.
  5. pip install processes the attacker-controlled dependency graph. Python package build or installation hooks may execute immediately.
  6. The installed code subsequently runs with the privileges of the user operating the agent.

Impact Assessment

Successful exploitation can ...[truncated 546 chars]

Remediation
View remediation

Remediation Suggestions

  • Include the reviewed implementation and dependency lock file directly in the Skill artifact.
  • If remote retrieval is unavoidable, pin the repository to a full verified commit hash rather than a mutable branch.
  • Prefer signed release artifacts and verify signatures or cryptographic checksums before execution.
  • Lock all direct and transitive Python dependencies to exact versions.
  • Install dependencies with verified hashes, such as through a hash-locked requirements file and pip --require-hashes.
  • Restrict installation to explicitly approved package indexes and disable unintended extra indexes.
  • Review package build metadata and avoid dependencies that require arbitrary installation hooks where possible.
  • Perform installation and execution in a sandbox with limited filesystem, network, and device access.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:12
Finding

Weather API Credentials Are Persisted in a Plaintext Configuration File

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:12-19
Vulnerability Type: Plaintext storage of sensitive credentials
Risk Level: Medium

Vulnerable snippet:

markdown
> **This skill writes durable state to the user's machine.** `init()` creates `~/.ac_controller/config.json` (API keys, device config, schedule templates) and starts a background scheduler daemon thread. The scheduler survives agent task completion — scheduled on/off times, auto-adjust, and storm auto-shutdown will continue to run autonomously. **Always confirm with the user before:**
> - Modifying or creating schedule templates
> - Enabling auto-adjust or typhoon auto-shutdown
> - Changing device configuration (brand, temperature rules, location)
>
> To fully disable automation: set `schedule_enabled=False` and `auto_adjust=False` for the device, then call `_cfg.save_config(_cfg.config)`.

The associated initialization example passes credentials directly into persistent configuration:

python
init(
    baidu_key="your_baidu_key",       # Baidu weather (default)
    # or use QWeather:
    # api_key="your_qw_key", qw_host="https://xxx.re.qweatherapi.com",
    location={"lat": 22.54, "lon": 114.05, "name": "Shenzhen"},
    brand="Gree"
)

Technical Analysis

The documentation explicitly states that API keys are stored in ~/.ac_controller/config.json. A normal JSON file provides no confidentiality by itself. The Skill does not document owner-only file permissions, encryption at rest, operating-system credential storage, credential lifecycle controls, or safeguards against exposing the file through logs and backups.

Persisting provider credentials may support unattended weather requests, but storing them alongside ordinary device and scheduling configuration grants broader access than necessary. Configuration-reading code needs access to both non-sensitive settings and credentials, increasing the ...[truncated 1229 chars]

Remediation
View remediation

Remediation Suggestions

  • Store API credentials in an operating-system credential manager or dedicated secret service.
  • Keep secrets separate from ordinary device, location, and schedule configuration.
  • If file-based storage is unavoidable, create the secret file atomically with owner-only permissions and verify those permissions before reading it.
  • Do not include API keys in logs, exceptions, telemetry, command output, or exported diagnostics.
  • Support environment-based or runtime secret injection so credentials need not be persisted.
  • Document credential revocation and rotation procedures.
  • Warn users that backups containing the configuration must be encrypted and access-controlled.
  • Minimize the privileges and provider scopes associated with each API key.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:32
Finding

Caller-Configurable Weather Host Creates a Potential Credential Exfiltration Boundary

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:32-35
Vulnerability Type: Unrestricted network destination for credentialed API requests
Risk Level: Medium

Vulnerable snippet:

python
init(
    baidu_key="your_baidu_key",       # Baidu weather (default)
    # or use QWeather:
    # api_key="your_qw_key", qw_host="https://xxx.re.qweatherapi.com",
    location={"lat": 22.54, "lon": 114.05, "name": "Shenzhen"},

Technical Analysis

The initialization interface accepts both an API key and a configurable qw_host. The documentation later states that weather requests are routed through the configured provider. If the implementation attaches the QWeather credential to requests made to the supplied host without strict validation, an attacker who can influence configuration can redirect credential-bearing traffic to an attacker-controlled server.

The documentation does not specify an allowlist of official provider domains, mandatory HTTPS validation, redirect restrictions, or controls preventing credentials from crossing origins. This means the network destination appears more configurable than necessary for ordinary QWeather functionality.

The executable implementation is not included in the artifact. Therefore, this audit cannot confirm the exact request construction, whether the API key is placed in headers or query parameters, or whether host validation exists in code. The confirmed design weakness is that sensitive credentials and a caller-selected network destination are exposed together without documented trust-boundary enforcement.

Attack Path

  1. An attacker influences an agent prompt, configuration import, or setup value used for qw_host.
  2. The agent initializes the Skill with a QWeather API key and the attacker-controlled host.
  3. The Skill persists that configuration.
  4. A weather function initiates a request using the configured host.
  5. If the implementation includes the API ...[truncated 756 chars]
Remediation
View remediation

Remediation Suggestions

  • Restrict qw_host to an explicit allowlist of official QWeather domains.
  • Normalize and validate the parsed URL rather than using string-prefix checks.
  • Require HTTPS and perform normal certificate and hostname validation.
  • Reject embedded credentials, nonstandard schemes, loopback addresses, link-local addresses, and private network destinations unless specifically required and separately authorized.
  • Do not forward API keys across redirects; reject redirects to origins outside the allowlist.
  • Bind each credential to its expected provider and destination.
  • Avoid accepting arbitrary host values from untrusted prompts or imported configuration.
  • Clearly document the exact network destinations and data fields transmitted.
  • Add tests proving that credentials cannot be sent to an unapproved origin.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The natural-language description on this line specifies that the skill supports Chinese and English names, but it does not present language selection as a user-controlled option. Under the policy rule, locale or language constraints should be optional or clearly justified; this wording suggests an implicit fixed language scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.