Back to skill

Security audit

Xiaomi

Security checks across malware telemetry and agentic risk

Overview

This skill is for legitimate Xiaomi device control, but it needs review because it handles sensitive device tokens and can change real appliance states without enough scoping or safety guidance.

Install only if you are comfortable letting an agent control Xiaomi devices on your LAN. Treat device tokens like passwords, do not store them in shared markdown or version control, inspect any token extractor before running it, and require explicit confirmation before power or appliance-state changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill defines broad natural-language intents that map directly to device-control commands without any stated confirmation, authorization, or device-scoping constraints. In a home-automation context, ambiguous triggers can cause unintended execution of high-impact actions such as powering appliances on or off, which may create safety, privacy, or physical-world risks.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill prominently instructs users to extract Xiaomi device IPs and tokens but does not warn that these tokens are sensitive secrets that grant LAN control over devices. Exposing, logging, or storing these credentials in markdown files can enable unauthorized control of smart-home devices and materially increases risk because the skill is specifically built around direct token-based device access.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.