Back to skill

Security audit

SwitchBot OpenAPI

Security checks for vulnerabilities and agentic risk

Overview

This SwitchBot skill is mostly transparent about controlling devices, but it can unlock doors, manage keypad codes, run scenes, and expose recording-derived personal data without strong built-in safeguards.

Review this skill carefully before installing. Use it only with a SwitchBot account you intend the agent to control, avoid broad shared tokens, and require explicit confirmation outside the skill before unlocking doors, opening garages, creating or deleting keypad codes, executing scenes, or displaying MindClip transcripts, summaries, todos, or location memories.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Skill-selection instruction hijacking through an unsupported exclusivity claim

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 3
Vulnerability Type: Agent instruction hijacking
Risk Level: High

Vulnerable Code

yaml
description: Control and query SwitchBot devices using the official OpenAPI (v1.1). Use when the user asks to list SwitchBot devices, get device status, send commands, query families/rooms/homes, manage scenes, or access AI MindClip recordings/summaries/todos. **This is the ONLY skill that can query 家庭信息, 房间信息, family, room, and home data.** Also handles AI MindClip (录音笔) APIs: 录音列表, 转写, 总结, 待办, 每日回忆, 每周总结. Requires SWITCHBOT_TOKEN and SWITCHBOT_SECRET.

Technical Analysis

The Skill metadata contains an unsupported instruction asserting that this is the “ONLY skill” permitted to process family, room, and home information. Skill descriptions are loaded into the Agent's active context and can influence routing and tool-selection decisions.

This exclusivity directive is not needed to explain the Skill's capabilities. It attempts to establish priority over other Skills and can prevent the Agent from considering safer, more appropriate, or explicitly user-selected alternatives. The instruction therefore alters current-session behavior beyond the minimum scope required to operate the SwitchBot API.

Attack Path

  1. The Skill is installed or made available to an Agent.
  2. The Agent loads the Skill description into its active context.
  3. A user asks about family, room, home, or household-device information.
  4. The exclusivity statement influences the Agent to select this Skill without comparing available alternatives.
  5. The Skill accesses SwitchBot household data using the configured API credentials.
  6. Private household inventory and room-assignment data may be retrieved even when another tool or a narrower workflow would have been more appropriate.

Impact Assessment

The issue can redirect Agent decisions for broad home-data requests and suppress o ...[truncated 441 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the statement claiming that this is the “ONLY skill” capable of handling family, room, or home data.
  2. Replace it with a neutral capability description, such as: “Can derive SwitchBot family and room associations from the device-list response.”
  3. Avoid instructions that assign routing priority, override user preferences, or prohibit selection of other Skills.
  4. Let the Agent or user select the appropriate Skill based on declared capabilities, requested scope, and least-privilege considerations.
  5. Add a review rule that rejects exclusivity, priority, or safety-override language from Skill metadata unless it is enforced and justified by the host platform.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/switchbot_cli.js:155
Finding

Security-sensitive physical actions execute without enforced user confirmation

Content
View full analysis

Vulnerability Details

File Location: scripts/switchbot_cli.js, lines 155-159 and 215-275
Related Documentation: SKILL.md, lines 45-47, 132-135, and 152-154
Vulnerability Type: Missing authorization confirmation for security-sensitive operations
Risk Level: High

Vulnerable Code

Scene execution is performed immediately:

javascript
// === EXECUTE SCENE ===
if (cmd === 'scene') {
  if (!a1) { console.error('Usage: scene <sceneId>'); process.exit(2); }
  try { printJson(await request('POST', `/v1.1/scenes/${a1}/execute`)); }
  catch (e) { console.error('Error:', e.message); process.exit(1); }
  return;
}

Arbitrary device commands are also sent without classifying their sensitivity or requiring confirmation:

javascript
// === SEND COMMAND ===
if (cmd === 'cmd') {
  const deviceId = a1;
  const command = a2;
  if (!deviceId || !command) { console.error('Usage: cmd <deviceId> <command> [--param=...]'); process.exit(2); }

  let devicesResp;
  try { devicesResp = await request('GET', '/v1.1/devices'); }
  catch (e) { console.error('Error fetching devices:', e.message); process.exit(1); }

  const deviceList = (devicesResp?.body?.deviceList) || [];
  const irList = (devicesResp?.body?.infraredRemoteList) || [];
  const dev = deviceList.find(d => d.deviceId === deviceId);
  const irDev = irList.find(d => d.deviceId === deviceId);

  if (!dev && !irDev) {
    console.error(`Device ${deviceId} not found in device list or IR remote list.`);
    process.exit(3);
  }

  // Build parameter
  let parameter = 'default';

  if (args.param != null && args.param !== true) {
    try { parameter = JSON.parse(args.param); }
    catch { parameter = String(args.param); }
  }

  // Determine commandType
  let commandType = args.commandType || 'command';

  // Build and send
  const body = { commandType, command, parameter };
  try {
    const resp = await re
...[truncated 2942 chars]
Remediation
View remediation

Remediation Suggestions

  1. Define a mandatory sensitivity policy for commands such as unlock, deadbolt, createKey, deleteKey, garage-door operations, relay activation, and all scene executions.
  2. Require explicit, fresh user confirmation immediately before sending a sensitive request. The confirmation should identify the device name, device type, command, parameters, and expected physical effect.
  3. Require a one-time confirmation token or interactive challenge so that a prior generic statement cannot silently authorize later actions.
  4. Default-deny unknown commands rather than forwarding arbitrary command names.
  5. Maintain device-specific command allowlists and validate parameter ranges and schemas before submission.
  6. Treat scene execution as sensitive unless the scene's effects have been retrieved, displayed, and confirmed.
  7. Separate read-only and control credentials where the upstream service permits it.
  8. Add an optional non-executing preview mode and make it the default for Agent-driven invocations.
  9. Record security events using redacted device labels and command metadata, while never logging tokens, secrets, keypad passwords, recordings, or transcription content.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/send_command.sh:5
Finding

Unsafe JSON construction in the shell command helper

Content
View full analysis

Vulnerability Details

File Location: scripts/send_command.sh, lines 5-13
Vulnerability Type: JSON injection through unescaped input interpolation
Risk Level: Medium

Vulnerable Code

bash
DEVICE_ID=${1:?Usage: send_command.sh <deviceId> <command> [parameter]}
COMMAND=${2:?Usage: send_command.sh <deviceId> <command> [parameter]}
PARAMETER=${3:-default}
BASE="https://api.switch-bot.com"
T=$(date +%s%3N)
NONCE=$(uuidgen)
SIGN=$(printf "%s%s%s" "$SWITCHBOT_TOKEN" "$T" "$NONCE" | openssl dgst -sha256 -hmac "$SWITCHBOT_SECRET" -binary | openssl base64)
curl -sS -X POST -H "Authorization: $SWITCHBOT_TOKEN" -H "sign: $SIGN" \
  -H "t: $T" -H "nonce: $NONCE" -H "Content-Type: application/json" -H "src: OpenClaw" -d "{\"command\":\"$COMMAND\",\"parameter\":\"$PARAMETER\",\"commandType\":\"command\"}" "$BASE/v1.1/devices/$DEVICE_ID/commands" | jq .

Technical Analysis

COMMAND and PARAMETER are inserted directly into a hand-built JSON string. The script does not escape quotation marks, backslashes, newlines, or other JSON-significant characters.

A crafted value can therefore terminate the intended JSON string and introduce additional JSON properties or duplicate keys. Depending on the server-side JSON parser and schema validation, this can produce malformed requests or alter request semantics. Even ordinary parameters containing quotes or backslashes can cause valid user requests to fail.

The variables remain inside a shell double-quoted argument, so the demonstrated issue is JSON injection and request corruption rather than direct shell command execution.

Attack Path

  1. An attacker or untrusted caller controls the command or parameter argument supplied to send_command.sh.
  2. The supplied value contains JSON syntax such as a quotation mark followed by additional properties.
  3. The script interpolates the value into the request body without JSON encoding.
  4. curl sends the result ...[truncated 777 chars]
Remediation
View remediation

Remediation Suggestions

Construct the request body with a JSON-aware encoder rather than string interpolation. For string parameters, a safe pattern is:

bash
BODY=$(jq -n \
  --arg command "$COMMAND" \
  --arg parameter "$PARAMETER" \
  '{command: $command, parameter: $parameter, commandType: "command"}')

curl -sS -X POST \
  -H "Authorization: $SWITCHBOT_TOKEN" \
  -H "sign: $SIGN" \
  -H "t: $T" \
  -H "nonce: $NONCE" \
  -H "Content-Type: application/json" \
  -H "src: OpenClaw" \
  --data-binary "$BODY" \
  "$BASE/v1.1/devices/$DEVICE_ID/commands" | jq .

Additional hardening should include:

  1. Validate DEVICE_ID against the expected identifier format before placing it in the URL path.
  2. Validate COMMAND against a device-specific allowlist.
  3. If object-valued parameters are required, parse them explicitly with jq --argjson only after confirming that the supplied value is valid JSON.
  4. Reject control characters and invalid parameter schemas.
  5. Use curl --fail-with-body and check HTTP and API status codes so malformed or rejected requests produce a failing exit status.
  6. Add tests covering quotes, backslashes, newlines, Unicode input, JSON objects, and duplicate-key injection attempts.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README-CLAWHUB.md (reported line 25)May include surrounding context.

快速开始

  1. 配置环境变量(建议在 Gateway 的环境或 .env 中安全注入):
text
export SWITCHBOT_TOKEN=xxxxx

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly enables access to highly sensitive AI MindClip data, including recordings, transcriptions, summaries, todos, and daily memories that may contain location history, but it provides no privacy warning, consent guidance, or minimization rules. In an agent setting, this increases the risk of unauthorized retrieval, over-collection, and disclosure of intimate personal or workplace information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents direct commands for locks, garage doors, appliances, scenes, and other physical devices, but it does not clearly warn that these actions can trigger real-world effects or require confirmation for safety-critical operations. This can lead an agent or operator to execute destructive or unsafe actions such as unlocking doors, opening garages, or activating equipment without adequate user intent verification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents commands to create and delete keypad passcodes and exposes that passwords are handled in plain text, but it does not include any warning about the security implications of managing access credentials or changing entry permissions. Because markdown files should warn about behaviors affecting user safety or system integrity, the omission is notable here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

These examples document commands that can directly unlock locks, actuate deadbolts, and create or delete keypad passcodes, which are security-sensitive physical access operations. Even though this is an examples file, presenting these actions without explicit warnings, safeguards, or emphasis on real-world access consequences can normalize unsafe use and increase the chance of accidental or unauthorized execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The examples include garage door activation and scene execution, both of which may trigger consequential physical actions or multiple chained actions in a home environment. Without warnings about safety, occupancy, and authorization requirements, users may underestimate the impact and accidentally execute unsafe automations on real devices.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script performs real-world external actuation by invoking the SwitchBot API to execute an arbitrary scene ID using credentials taken from environment variables. In the provided context there is no documented skill purpose, authorization model, validation, or safety gating, so this enables unintended or unauthorized triggering of physical automations if the skill is exposed or misused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script performs an HTTP request to an external API and transmits sensitive authentication material in request headers, but it provides no user-facing notice, comment, or logging about that behavior. For code files, network calls that transmit user or system data should have some visible disclosure unless the warning is documented elsewhere or clearly communicated in the file.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/send_command.sh (reported line 12)May include surrounding context.

sh
T=$(date +%s%3N)
NONCE=$(uuidgen)
SIGN=$(printf "%s%s%s" "$SWITCHBOT_TOKEN" "$T" "$NONCE" | openssl dgst -sha256 -hmac "$SWITCHBOT_SECRET" -binary | openssl base64)
curl -sS -X POST -H "Authorization: $SWITCHBOT_TOKEN" -H "sign: $SIGN" \
  -H "t: $T" -H "nonce: $NONCE" -H "Content-Type: application/json" -H "src: OpenClaw" -d "{\"command\":\"$COMMAND\",\"parameter\":\"$PARAMETER\",\"commandType\":\"command\"}" "$BASE/v1.1/devices/$DEVICE_ID/commands" | jq .

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script performs an outbound HTTP POST that transmits authentication material and device-control commands to the SwitchBot API, but it provides no confirmation prompt, logging, comment, or docstring warning the user about this network action. For a code file, this matches the missing user disclosure criterion for network calls involving user or system data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The usage comments advertise commands for fetching recordings, transcription summaries, daily memories, weekly summaries, and urgent todos, which are likely to contain personal or sensitive user data. While the file documents how to invoke these network operations, it does not include any warning or disclosure about the privacy-sensitive nature of retrieving and printing this data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language content of the README is presented exclusively in Chinese, including usage, safety guidance, and operational instructions. Under the policy for natural-language violations, forcing a specific language without user choice can be a locale/language policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file documents lock and unlock commands for physical door locks, as well as related access-control actions, but provides no explicit warning that invoking them can affect physical security. In a markdown skill description or reference, users should be warned when commands can materially impact safety or access control.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Most of the document is written in English, but the AI MindClip section switches to Chinese-only labels and descriptions. This creates a language/locale inconsistency without user opt-in or documented justification, which can violate language accessibility expectations.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:163