Back to skill

Security audit

agentpass

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Home Assistant control gateway that uses human approval for state-changing actions, with a normal but noteworthy third-party CLI dependency risk.

Before installing, confirm you trust the agentpass package source and use a narrowly scoped AGENT_TOKEN. Expect the skill to read Home Assistant states, history, logbook, services, and configuration, and to request Telegram guardian approval before changing device state.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:6
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 6
Vulnerability Type: Unpinned dependency installation from a package registry
Risk Level: Medium

Vulnerable Code Snippet:

yaml
metadata: {"openclaw":{"emoji":"🔐","os":["linux","darwin"],"requires":{"bins":["agentpass"],"env":["AGENTPASS_URL","AGENT_TOKEN"]},"install":[{"id":"pip-agentpass","kind":"uv","package":"agentpass","bins":["agentpass"],"label":"Install agentpass CLI"}]}}

Technical Analysis

The installation metadata requests the agentpass package by name without specifying an exact version or verifying a package hash. Consequently, the installed artifact depends on whichever release the configured package registry resolves at installation time.

This creates a supply-chain risk because the installed code can change independently of the reviewed skill. A compromised maintainer account, compromised package registry, malicious future release, or dependency-resolution manipulation could cause users to install code that was not covered by this audit.

This finding does not establish that the current agentpass package is malicious. The weakness is the absence of deterministic version and integrity controls when obtaining executable third-party code.

Attack Path

  1. An attacker compromises the package publisher, distribution account, registry, or another relevant dependency-distribution component.
  2. The attacker publishes a malicious release under the expected agentpass package name.
  3. A user or skill manager processes the installation declaration and resolves package: "agentpass" to the attacker-controlled release.
  4. The package is installed and its agentpass executable is subsequently invoked according to the instructions in SKILL.md.
  5. The malicious executable runs with the privileges of the process invoking the skill and can access resources available to that process.

Impact Assessment

Successful exploitat ...[truncated 690 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin agentpass to a specific, reviewed version rather than resolving the latest available release.
  • Require cryptographic hash verification for the exact package artifact where the installation framework supports it.
  • Use a lockfile or equivalent reproducible dependency manifest that records resolved versions and integrity hashes, including transitive dependencies.
  • Retrieve packages only from an explicitly configured, trusted registry or an internally controlled package mirror.
  • Review package provenance and signatures before updating the pinned version.
  • Run the installed CLI under a dedicated, least-privileged account or sandbox with minimal filesystem and network access.
  • Provide AGENT_TOKEN only to the command that requires it, use a narrowly scoped token, and avoid exposing the token to unrelated installation hooks or processes.
  • Add automated dependency monitoring, but require security review before accepting package updates.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
## Available Tools

### Read-only (auto-approved, instant)

**Get a single entity state:**

Static analysis

No suspicious patterns detected.