pp-home-assistant
Warn
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill implements a
--deliver webhook:<url>feature that allows the agent to POST command results (including household states, history, and configuration) to any external URL. While designed for orchestration, this provides a native mechanism for exfiltrating sensitive household data. - [COMMAND_EXECUTION]: The skill uses an "Automatic learning" loop that synthesizes "playbooks" consisting of CLI command sequences with string substitution (
{slot}). These playbooks are replayed from a local store (data.db,learn_events). If an attacker can influence the data being "taught" (e.g., via malicious device names or crafted automation failure logs), it could lead to the execution of unintended commands during playbook replay. - [PROMPT_INJECTION]: The skill processes large amounts of untrusted data from the Home Assistant instance, including entity states, logbook entries, and event histories. This constitutes a significant surface for indirect prompt injection, as malicious data injected into Home Assistant could influence the agent's decision-making process.
- Ingestion points: Reads logs, states, history, and events via
home-assistant-pp-cli(SKILL.md). - Boundary markers: No specific delimiters or "ignore instructions" warnings are mentioned for the external data being processed.
- Capability inventory: Includes smart home control (
services call), file writing (--deliver file:), and network requests (--deliver webhook:). - Sanitization: No sanitization or validation of the retrieved Home Assistant data is documented.
- [EXTERNAL_DOWNLOADS]: The skill installs binary tools and packages from the
@mvanhornNPM namespace and thegithub.com/mvanhornrepository. These are identified as vendor-owned resources corresponding to the developer's ecosystem and are used for core skill functionality.
Audit Metadata