Audit-Verlauf
home-assistant-manager - 9 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v9 Neueste | 9. Juli 2026, 16:31 | 2 bestätigt | 33 | Keine Änderung der Fähigkeiten |
| v8 | 9. Juli 2026, 16:31 | 2 bestätigt | 33 | Keine Änderung der Fähigkeiten |
| v7 | 5. Juli 2026, 18:12 | 2 bestätigt | 33 | Keine Änderung der Fähigkeiten |
| v6 | 30. Juni 2026, 05:50 | Keine bestätigten Befunde | 4 | Keine Änderung der Fähigkeiten |
| v5 | 17. Jan. 2026, 08:06 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v4 | 17. Jan. 2026, 08:06 | Keine bestätigten Befunde | 0 | NetzwerkzugriffDateisystemzugriffUmgebungsvariablenExterne Befehle |
| v3 | 8. Jan. 2026, 02:47 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v2 | 8. Jan. 2026, 02:47 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v1 | 8. Jan. 2026, 02:47 | Keine bestätigten Befunde | 0 | Ausgangsbasis |
9. Juli 2026, 16:31
The skill is not malicious, but it intentionally guides privileged Home Assistant operations through SSH, hass-cli, git, and scp. Confirmed risks center on remote command execution, writing Home Assistant .storage files, persistent token setup, and commands that can affect real devices; many scanner hits were Markdown, template, or screenshot false positives. No prompt injection attempt was found in the reviewed files.
Bestätigte Sicherheitsbedenken (2)
Elemente der Fähigkeitsprüfung (33)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
🌐 Netzwerkzugriff (3)
📁 Dateisystemzugriff (8)
🔑 Umgebungsvariablen (1)
⚙️ Externe Befehle (88)
9. Juli 2026, 16:31
The skill is not malicious, but it intentionally guides privileged Home Assistant operations through SSH, hass-cli, git, and scp. Confirmed risks center on remote command execution, writing Home Assistant .storage files, persistent token setup, and commands that can affect real devices; many scanner hits were Markdown, template, or screenshot false positives. No prompt injection attempt was found in the reviewed files.
Bestätigte Sicherheitsbedenken (2)
Elemente der Fähigkeitsprüfung (33)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
🌐 Netzwerkzugriff (3)
📁 Dateisystemzugriff (8)
🔑 Umgebungsvariablen (1)
⚙️ Externe Befehle (88)
5. Juli 2026, 18:12
The package is a Markdown skill with a supporting dashboard image and no prompt injection text found in the reviewed files. Many static matches are Markdown formatting or documentation placeholders, but the skill intentionally guides agents through SSH, scp, git, hass-cli, and Home Assistant restart workflows. This should require explicit command review, scoped credentials, and careful handling of Home Assistant storage files.
Bestätigte Sicherheitsbedenken (2)
Elemente der Fähigkeitsprüfung (33)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
🌐 Netzwerkzugriff (3)
📁 Dateisystemzugriff (8)
🔑 Umgebungsvariablen (1)
⚙️ Externe Befehle (88)
30. Juni 2026, 05:50
Static analysis reported many high-risk patterns, but review found no executable source code or prompt-injection attempt. Most command findings are Markdown examples, while the skill still legitimately directs SSH, scp, hass-cli, token, and Home Assistant storage workflows that can change a live instance.
Elemente der Fähigkeitsprüfung (4)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Statische falsch positive Treffer ignoriert (1)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
Risikofaktoren
⚙️ Externe Befehle (5)
🌐 Netzwerkzugriff (4)
📁 Dateisystemzugriff (4)
🔑 Umgebungsvariablen (4)
Erkannte Muster
17. Jan. 2026, 08:06
This is a pure prompt-based skill containing only documentation (SKILL.md, README.md) with example commands and configuration patterns. No executable code, scripts, or direct system access is performed by the skill itself. The static analyzer flagged markdown code fences as 'backtick execution' and documentation links as 'hardcoded URLs' - all false positives from documentation pattern matching. The skill provides Claude with expert knowledge about Home Assistant management workflows.
Risikofaktoren
🌐 Netzwerkzugriff (1)
📁 Dateisystemzugriff (1)
🔑 Umgebungsvariablen (1)
⚙️ Externe Befehle (1)
17. Jan. 2026, 08:06
This is a pure prompt-based skill containing only documentation (SKILL.md, README.md) with example commands and configuration patterns. No executable code, scripts, or direct system access is performed by the skill itself. The static analyzer flagged markdown code fences as 'backtick execution' and documentation links as 'hardcoded URLs' - all false positives from documentation pattern matching. The skill provides Claude with expert knowledge about Home Assistant management workflows.
Risikofaktoren
🌐 Netzwerkzugriff (1)
📁 Dateisystemzugriff (1)
🔑 Umgebungsvariablen (1)
⚙️ Externe Befehle (1)
8. Jan. 2026, 02:47
This is a pure prompt-based skill containing only documentation and guidance. No executable code, scripts, network calls, or file system access is performed by the skill itself. The skill provides Claude with expert knowledge about Home Assistant management workflows.
8. Jan. 2026, 02:47
This is a pure prompt-based skill containing only documentation and guidance. No executable code, scripts, network calls, or file system access is performed by the skill itself. The skill provides Claude with expert knowledge about Home Assistant management workflows.
8. Jan. 2026, 02:47
This is a pure prompt-based skill containing only documentation and guidance. No executable code, scripts, network calls, or file system access is performed by the skill itself. The skill provides Claude with expert knowledge about Home Assistant management workflows.