Back to skill

Security audit

Nanoleaf (Picoleaf)

Security checks for vulnerabilities and agentic risk

Overview

This Nanoleaf skill is purpose-aligned, but its install options can place an unverified third-party executable on your machine and it stores a local device token in plaintext.

Review the install path carefully before installing. Prefer a verified, pinned Picoleaf source if available, inspect any Homebrew formula or downloaded archive before use, and create ~/.picoleafrc with owner-only permissions such as mode 600 because it contains a reusable local device access token.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:5
Finding

Unverified Remote Executable Download and Installation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Picoleaf Installation Trusts an Unpinned Personal Homebrew Tap

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:16
Finding

Nanoleaf Access Token Stored Without Required File-Permission Hardening

Content
View full analysis
:16021 access_token= ``` ``` ### Technical Analysis The setup instructions direct the user to store the Nanoleaf access token in plaintext in `~/.picoleafrc`, but do not require a restrictive creation mask or file mode. Plaintext storage may be required by the client, but access should be limited to the owning user. The actual exposure depends on how the file is created and the user's default `umask`. If it is group-readable, world-readable, included in backups with broad access, or otherwise exposed to another local principal, that principal can recover the token. The token-generation request is directed to the Nanoleaf device on the local network and no external exfiltration instruction was identified. The issue is specifically the omission of local file-access hardening. ### Attack Path 1. The user creates `~/.picoleafrc` while operating under a permissive default `umask`, or creates it through tooling that preserves broad permissions. 2. Another local user, process, backup consumer, or compromised application reads the configuration file. 3. The attacker extracts the `host` and `access_token` values. 4. While able to reach the Nanoleaf device, the attacker sends authenticated API requests or uses Picoleaf to control it. ### Impact Assessment The exposed token permits unauthorized control within the capabilities granted by the Nanoleaf local API, including changing power, brightness, colors, and related device settings. This does not by itself demonstrate operating-system privilege escalation, but it compromises the confidentiality of an authentication credential and the integrity and availability of the lighting device. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill instructs users to persist a long-lived Nanoleaf access token in a plaintext file under the home directory. While this is common CLI behavior, it creates a reusable local credential that could be stolen by other local users, malware, backups, or overly permissive file permissions and then used to control the device on the local network.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

  1. Find Nanoleaf IP: Check router or use mDNS: dns-sd -Z _nanoleafapi
  2. Generate token: Hold power button 5-7 sec until LED flashes, then within 30 sec run: curl -iLX POST http://<ip>:16021/api/v1/new
  3. Create config file ~/.picoleafrc:
    ini
    host=<ip>:16021
    access_token=<token>
    

Static analysis

No suspicious patterns detected.