HA Integration Dev

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Security
SecurityMEDIUM
references/conversation-agent.md

No direct signs of intentional malware (e.g., credential theft, backdoors, or external exfiltration) are present in the shown code. However, the LLM-based agent introduces a significant security risk: untrusted LLM output is loosely parsed and can directly trigger Home Assistant service calls (domain/service/entity_id/data) without allowlisting or schema validation, creating a prompt-injection/LLM-output-to-automation-execution threat. It also embeds home entity state into the LLM prompt, potentially leaking home metadata to the LLM endpoint. This should be reviewed and constrained before production use.

Confidence: 66%Severity: 70%
Audit Metadata
Analyzed At
Apr 17, 2026, 08:29 AM
Package URL
pkg:socket/skills-sh/tonylofgren%2Fsupercharge-smart-home-claude-skills%2Fha-integration-dev%2F@7c7f73da5e70672f1e5966e388889de4a005359c