homeassistant-mcp-server

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly aligned with its stated Home Assistant control purpose and does not show obvious credential theft or third-party proxying. Main concerns are the broad real-world action surface, plaintext long-lived token handling, and a publisher/provenance mismatch between ara.so and the referenced robbrad package/repo. Overall this is better classified as suspicious/high-impact rather than malicious.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
May 17, 2026, 03:53 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fhomeassistant-mcp-server%2F@f9914f089c61a4710312335efa829632efce7e80
Security Audit — socket — homeassistant-mcp-server