pp-home-assistant

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the home-assistant-pp-cli and home-assistant-pp-mcp tools. These are fetched via npx and go install from official vendor-maintained repositories and packages. These downloads are required for the skill's operational capabilities.
  • [COMMAND_EXECUTION]: Employs a CLI tool to execute household management tasks. The tool includes a --deliver flag that allows routing command output to specific sinks, including local files or webhooks, which is a documented feature for flexible data integration.
  • [PROMPT_INJECTION]: The skill processes household metadata, entity names, and logs from a Home Assistant instance. Although this represents an ingestion of external data, the skill mitigates risks by using structured JSON output (--agent mode) for agent consumption and provides explicit warnings to strip personally identifiable information (PII) before using its learning features.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 09:18 AM
Security Audit — agent-trust-hub — pp-home-assistant