T01 · Skill Instruction Hijacking
- Location
setup.sh:42- Finding
Persistent Agent Instruction Injection Through Untrusted LIFX Metadata
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but it stores a smart-home API token locally and can turn untrusted LIFX device names into persistent agent instructions.
Install only if you are comfortable giving this skill ongoing control of your LIFX lights and storing a reusable LIFX token on disk. Prefer using an environment secret instead of setup.sh <token>, do not commit or copy .lifx-token, review generated SKILL.md before use, and avoid device or scene names that contain Markdown, newlines, or instruction-like text.
setup.sh:42Persistent Agent Instruction Injection Through Untrusted LIFX Metadata
setup.sh:16LIFX Bearer Token Exposed Through Process Arguments and Plaintext Storage
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
def api(token: str, path: str) -> Any:
r = requests.get(f"{LIFX_API}{path}", headers={"Authorization": f"Bearer {token}"}, timeout=15)
r.raise_for_status()
return r.json()
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
### 1. Get your LIFX token
Go to [cloud.lifx.com/settings](https://cloud.lifx.com/settings) and generate a personal access token.
### 2. Run setup
The skill instructs users to run setup that stores a LIFX API token locally, queries cloud APIs, discovers home devices/scenes, and rewrites SKILL.md with personalized context, but those data-handling behaviors are not clearly disclosed in the primary description. Undeclared storage of credentials and home-device metadata can surprise users and create privacy and secret-management risks, especially in shared repositories or agent workspaces.
The skill instructs users to run setup that stores a LIFX API token locally, queries cloud APIs, discovers home devices/scenes, and rewrites SKILL.md with personalized context, but those data-handling behaviors are not clearly disclosed in the primary description. Undeclared storage of credentials and home-device metadata can surprise users and create privacy and secret-management risks, especially in shared repositories or agent workspaces.
Referenced artifact was not completely inspected
This discovers your lights, groups, and scenes, then generates a personalized `SKILL.md` with your device context.
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
local tmpfile
tmpfile=$(mktemp)
http_code=$(curl -s -o "$tmpfile" -w "%{http_code}" \
-X "$method" \
-H "Authorization: Bearer ${TOKEN}" \
-H "Content-Type: application/json" \
The README instructs users to pass a personal LIFX access token into setup and says the script performs device discovery and generates local files, but it does not clearly warn that this stores the token locally and initiates network calls against the user's LIFX account. In an agent-skill context, insufficient disclosure is security-relevant because users may expose credentials on disk or through shell history without understanding the trust boundary.
The skill declares access to a sensitive environment variable (LIFX_TOKEN) and instructs use of shell scripts and outbound API calls, but it does not define any explicit tool scope such as allowed tools or permissions. In an agent environment, missing scope boundaries can let the skill invoke broader shell/network capabilities than users expect, increasing the blast radius if the skill or its surrounding tooling is abused.
The documentation says setup.sh rewrites SKILL.md with discovered lights, rooms, scenes, and location context, but it does not warn that this embeds personal household metadata into a project file. That can expose sensitive occupancy, naming, or location information through source control, logs, backups, or sharing of the skill directory.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
#!/bin/bash
set -euo pipefail
API="https://api.lifx.com/v1"
TOKEN="${LIFX_TOKEN:-}"
# Load token from skill directory if not set
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
#!/bin/bash
set -euo pipefail
API="https://api.lifx.com/v1"
TOKEN="${LIFX_TOKEN:-}"
# Load token from skill directory if not set
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
#!/bin/bash
set -euo pipefail
API="https://api.lifx.com/v1"
TOKEN="${LIFX_TOKEN:-}"
# Load token from skill directory if not set
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
#!/bin/bash
set -euo pipefail
API="https://api.lifx.com/v1"
TOKEN="${LIFX_TOKEN:-}"
# Load token from skill directory if not set
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
#!/bin/bash
set -euo pipefail
API="https://api.lifx.com/v1"
TOKEN="${LIFX_TOKEN:-}"
# Load token from skill directory if not set
The script loads authentication material from a local .lifx-token file if the environment variable is absent. This expands the credential surface beyond the stated skill behavior and can lead to unintended use of locally stored secrets, especially in shared or multi-skill environments where neighboring files may be readable or mistakenly packaged.
The script persists the LIFX bearer token to disk in a local file, which creates a credential-at-rest risk if the skill directory is later copied, backed up, committed, or read by another process running as the same user. Although chmod 600 limits access to the current account, the user is not meaningfully warned that a reusable cloud API credential will be stored locally for ongoing use.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Save token
echo "$TOKEN" > "$SKILL_DIR/.lifx-token"
chmod 600 "$SKILL_DIR/.lifx-token"
echo "🔑 Token saved to .lifx-token"
# Generate device context
No suspicious patterns detected.