other
- Location
scripts/iot_controller.py:53- Finding
Environment Credential Exfiltration to Arbitrary Network Endpoints
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill gives an agent broad Windows, network, camera, microphone, GUI, and smart-home control, but its scope and safety controls are too broad and inconsistent for routine installation.
Install only if you intentionally want a powerful local Windows automation and device-control skill. Review every command before execution, avoid using it with untrusted prompts or webpages, do not expose `HA_TOKEN` unless the Home Assistant URL is fixed and trusted, and treat Wi-Fi password display, camera/microphone capture, process killing, network changes, and smart-home actions as sensitive operations requiring explicit consent.
scripts/iot_controller.py:53Environment Credential Exfiltration to Arbitrary Network Endpoints
scripts/network_controller.py:174PowerShell Command Injection Through Wi-Fi SSID Parameters
scripts/battery_controller.py:191PowerShell Command Injection Through Power-Plan Name
scripts/network_controller.py:264Saved Wi-Fi Password Disclosure Without Confirmation or Redaction
scripts/process_manager.py:132Destructive Process and Window Operations Bypass Declared Confirmation Requirements
scripts/camera_controller.py:52Automatic Runtime Installation of Mutable Third-Party Dependencies
There is a strong description-behavior mismatch. The declared description presents a sweeping, universal, multi-layer skill with orchestration and broad system-control capabilities across numerous device classes and task types. The supplied code, however, is limited to audio management on Windows: enumerating sound devices, changing default audio endpoints, controlling volume, and recording microphone input. While audio devices are one subset mentioned in the description, the actual code does not implement the vast majority of the declared capabilities, nor any general-purpose orchestration or cognition framework. This is not merely over-declaration of permissions; the primary purpose described is materially broader and different from the code’s actual narrow behavior.
The declared description vastly overstates the skill's functionality. The supplied code only implements battery and Windows power-management operations: querying battery information, listing/getting/setting power plans, and generating a battery report. It does not provide a general orchestration engine, arbitrary code generation/execution framework, broad software/hardware control, or universal task applicability. While battery/power control is one small subset of the declared system-control layer, the actual code is materially narrower than the description, so the description does not accurately represent the code's real behavior.
There is a clear description-behavior mismatch. The description claims an extremely broad, unified, all-capable system spanning cognition, execution, orchestration, and control of many classes of software and hardware. The actual code chunk only implements Bluetooth-related device management functions. While Bluetooth control is one small subset of the declared scope, the declared primary purpose is materially broader and presented as universally applicable without exception. The code does not contain the claimed orchestration engine, general execution framework, or the many other device/system control domains listed. This is not merely over-declared permission; it is a materially inaccurate representation of the code's real behavior.
The supplied code does not implement a general-purpose omnipotent skill. It only provides camera-specific functionality: enumerating cameras via WMI/OpenCV, inspecting camera properties, and capturing a still image. Although it uses subprocess/pip installation and PowerShell for support tasks, these are implementation details in service of camera management, not evidence of the declared broad execution framework or universal orchestration engine. The description materially overstates the scope and primary purpose, claiming sweeping device/system control and applicability to any task, while the actual code is limited to webcam access and image capture on Windows.
There is a clear description-behavior mismatch. The declared purpose advertises a massive multi-layer capability suite with reasoning modes, execution framework, orchestration, and direct control over numerous hardware/software domains. The supplied code does not implement those capabilities. It only exposes helper functions to run PowerShell and guarded shell commands plus a tiny serialization helper. While command execution could be a supporting building block for a larger system controller, this chunk by itself does not demonstrate the claimed orchestration engine, broad device-control interfaces, cognition layer, or universal applicability. This is not merely incomplete detail; the actual code's primary purpose is much narrower than the declared description.
The description vastly overstates the skill's purpose and scope. The code chunk only implements monitor/display-related operations on Windows: querying display info, multi-monitor layout, DPI, Night Light, and orientation. There is no evidence in this code of a general cognition suite, LLM-based automation, arbitrary command execution, orchestration across primitive actions, or control of the many other listed hardware/software domains. While 'display/monitor' control is one small subset of the declared description, the declared primary purpose is materially different and much broader than the actual behavior shown. Therefore this is a clear description-behavior mismatch.
The description massively overstates the skill's scope. The actual code implements a specific GPU utility for Windows focused on NVIDIA GPUs and nvidia-smi. It can monitor GPU state and adjust GPU power limits, but it does not implement the broad multi-layer cognitive/execution/orchestration platform described. There is no evidence of LLM integration, arbitrary command execution exposed as a feature, desktop app automation, system-wide hardware control across the listed device categories, or universal task applicability. While GPU control is one small subset of the declared hardware-control claims, the primary purpose and actual resource access are materially narrower than declared, so this is a clear description-behavior mismatch.
该描述与代码行为存在明显不匹配。代码内容聚焦于桌面 GUI 自动化:通过 pyautogui 执行鼠标/键盘输入、截图、OCR、图像定位与点击、颜色检测,并借助 PowerShell 获取前台窗口坐标或提供 OCR 回退信息。这确实涉及一小部分“Windows桌面软件/图形界面自动化”能力,但远不足以支撑声明中的广泛能力版图。声明将技能描述为通用认知+执行+系统/硬件全控制+编排引擎的“全知全能”套件,而实际代码没有任何认知推理模块、LLM 集成、任意命令执行接口、硬件设备管理接口或复杂编排框架。根据评估标准,这是对主要用途和能力范围的重大夸大,属于描述与实际行为不一致。
There is a strong description-behavior mismatch. The declared purpose presents a sweeping, universal capability stack spanning cognition, execution, system control, and orchestration across many hardware and software domains. The supplied code does not implement anything close to that breadth. Instead, it is a single-purpose Windows hardware control utility with a constrained CLI and a limited set of actions: audio volume/mute, brightness, display info, power operations, and USB listing. While some of these actions partially overlap the broad 'system/hardware control' claims, the vast majority of declared capabilities are absent, including LLM-based automation, general orchestration, GUI automation, Bluetooth, serial, IoT, storage, printers, cameras, fan/temperature control, and broad arbitrary-task execution. The primary purpose of the code is materially narrower than the description.
The description dramatically overstates the skill's purpose relative to the code provided. The code only enumerates input devices on Windows: keyboards, mice, and gamepads. It does not control devices, execute arbitrary automation chains, provide a cognition layer, manage software, or interact with the many hardware/resource categories claimed in the description. While over-declared permissions alone should not trigger a mismatch, this is not merely overbroad wording—the declared primary purpose is materially different from the actual behavior. Therefore this is a clear description-behavior mismatch.
该描述与代码行为存在明显且重大的不一致。描述宣称这是一个几乎无所不能的综合技能,涵盖认知、代码生成执行、系统级控制和广泛硬件/外设操控,并具有通用编排能力;但代码只是单一用途的 IoT 控制 CLI,核心功能是向 Home Assistant 或任意 HTTP 端点发送请求,以及输出 Mijia 发现说明。虽然“物联网平台控制”这一小部分与声明有局部重合,但其余绝大多数关键能力均未在代码中出现,且代码的主要目的与“全知全能、适用于任何任务”的定位严重不符,因此应判定为描述夸大且失实的能力声明。
The supplied code does not implement a general-purpose omnipotent skill. It specifically manages Windows networking: listing/enabling/disabling adapters, scanning/connecting/disconnecting WiFi, showing WiFi profiles (including cleartext key display), reading and setting DNS, reading and setting proxy settings, and ping tests. While these actions fit a small subset of the declared 'system control' theme, the description materially overstates the implemented scope and primary purpose. There is no evidence here of cognition modules, broad command-execution automation, arbitrary task orchestration, or control of the many other claimed device/resource categories. Therefore the description does not accurately represent the actual behavior.
The declared description vastly overstates the skill's scope and purpose. The supplied code implements only printer-related operations on Windows via built-in PowerShell/CIM interfaces: enumerating printers, reading/changing the default printer, listing and cancelling print jobs, and retrieving printer capabilities. It does not provide a general orchestration engine, reasoning framework, code generation/execution framework, or broad system/hardware control across the many resource types listed. While printer control is one small subset mentioned in the description, the declared purpose says the skill can handle essentially any task with integrated cognition, execution, and system control, which is materially inaccurate for this code chunk.
该描述与代码行为明显不符。代码的核心用途是本地 Windows 进程管理与少量系统状态查询,而描述宣称的是一个覆盖几乎所有任务和多种系统/硬件控制面的通用“全知全能”技能。虽然代码确实涉及部分系统控制(启动/终止进程、查看资源),与描述中的“系统控制”大类存在很弱的重叠,但远不足以支撑其所宣称的广泛能力范围。未发现代码实现认知层思维操作码、编排引擎、GUI 自动化、硬件外设控制、物联网/蓝牙/GPU/磁盘/电源等关键能力,因此应判定为描述与实际行为存在重大不匹配。
There is a clear description-behavior mismatch. The declared purpose presents a sweeping, all-capable platform covering reasoning modes, automation, orchestration, and control of many categories of software and hardware. The supplied code does only three scanner-related tasks on Windows: list scanner devices via WIA/WSD/PnP, show WIA device information, and report WIA service availability. While the code does access a limited hardware-related area (scanner/image devices) using PowerShell and Windows services/registry/PnP, that is only a tiny subset of the declared functionality. The primary purpose is scanner enumeration and status inspection, not a universal execution/control engine.
The supplied code does not implement the vast majority of the declared capabilities. Its real purpose is limited to serial device communication via pyserial, with a small CLI exposing list/detect/send/receive/chat/monitor operations. While serial-device interaction is one small subset of the declared hardware/control claims, the description presents a general-purpose omnipotent execution and orchestration suite applicable to any task, which is materially inaccurate for this code chunk. The only notable extra behavior is automatic installation of pyserial via pip, which is a supporting implementation detail rather than the primary mismatch. Therefore the description substantially overstates and misrepresents the code's actual behavior.
There is a clear description-behavior mismatch. The declaration presents an extremely broad, omnipotent multi-layer skill covering reasoning, execution, orchestration, and control of many system and hardware domains. The actual code chunk implements only storage-related read/analysis operations on Windows: drive listing, drive info, health/status queries, large-file search, folder usage analysis, and partition enumeration. It does not implement the vast majority of the declared capabilities, nor does it support arbitrary tasks. While the code does interact with one declared domain (storage disks), the declared purpose materially overstates the skill’s scope and primary function.
There is a clear description-behavior mismatch. The description advertises a comprehensive omnipotent skill with broad cross-domain control and orchestration capabilities, while the actual code is limited to thermal status inspection and monitoring on Windows. The code gathers telemetry via psutil, WMI/CIM, and nvidia-smi, and returns JSON for status, CPU info, fan info, and sampled monitoring data. It does not implement the vast majority of the declared capabilities, especially arbitrary task execution, GUI/device control, IoT/Bluetooth/serial integrations, or generalized orchestration. Although thermal/fan monitoring is one small subset of the declared hardware scope, the declared purpose materially overstates the implemented behavior.
该描述与代码行为明显不符。代码块的主用途是 Windows 桌面窗口控制,而非一个覆盖所有任务的“全知全能”技能。虽然声明中提到“Windows桌面软件/图形界面自动化”,这与代码的部分能力有交集,但代码只提供非常具体且有限的窗口管理与发送按键功能,没有实现声明中绝大多数能力层:没有认知套件、没有 LLM 驱动的代码生成或通用脚本执行、没有硬件/IoT/蓝牙/GPU/磁盘等控制、也没有编排引擎。因此这是对能力范围和主要用途的重大夸大,属于显著不匹配。
The skill prominently advertises sensitive system-control abilities—hardware, desktop software, network, Bluetooth, storage, audio, display, printers, cameras, and IoT—without equally prominent privacy and safety warnings at the point of description. In context, this is dangerous because the skill is framed as universally applicable, encouraging broad use of surveillance-capable and system-impacting functions without informed consent boundaries.
The skill declares an extremely broad activation scope—'applies to any task, without exception'—for a capability set that includes code execution, shell commands, file/network access, GUI automation, device control, and IoT actions. Such unconstrained triggering significantly raises the risk of the agent invoking powerful operations in inappropriate contexts, including privacy-sensitive or destructive tasks, with insufficient narrowing or human review.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| 级别 | 示例 | 处理方式 |
|------|------|----------|
| 🔴 高危 | `rm -rf /`、`format C:` | **必须用户确认** |
| 🟡 中危 | `pip uninstall`、`sudo` | 警告提示 |
| 🟢 低危 | `ls`、`cat`、`python script.py` | 直接执行 |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| 级别 | 示例 | 处理方式 |
|------|------|----------|
| 🔴 高危 | `rm -rf /`、`format C:` | **必须用户确认** |
| 🟡 中危 | `pip uninstall`、`sudo` | 警告提示 |
| 🟢 低危 | `ls`、`cat`、`python script.py` | 直接执行 |
This is a true tool-parameter abuse risk because the wrapper exposes shell execution as a reusable primitive and relies on weak filtering instead of safe process invocation. Within a powerful orchestration skill that can operate across system components, a generic shell-capable helper materially increases the blast radius of any upstream validation mistake.
return "", f"ERROR: Command blocked - contains '{blocked}'", -1
try:
result = subprocess.run(
cmd, shell=True, capture_output=True, text=True,
encoding="utf-8", errors="replace", timeout=timeout
)
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
Returns:
Tuple of (stdout: str, stderr: str, returncode: int)
"""
env = os.environ.copy()
env["PYTHONIOENCODING"] = "utf-8"
# Prepend encoding setup to ensure UTF-8 output
No suspicious patterns detected.