home-automation

Pass

Audited by Gen Agent Trust Hub on Mar 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSNO_CODEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill does not contain any malicious code, obfuscation, or attempts to bypass agent safety guidelines.\n- [EXTERNAL_DOWNLOADS]: The skill references official and well-known API endpoints for Google Home (googleapis.com) and Home Assistant services for device management and authentication.\n- [NO_CODE]: No executable script files or binary dependencies are included with this skill; it consists entirely of markdown-based instructions and code snippets.\n- [PROMPT_INJECTION]: The skill presents a standard attack surface for indirect prompt injection due to its core function of ingesting data from external IoT devices.\n- Ingestion points: Device states and metadata are retrieved from external IoT platforms via the Home Assistant and Google Home Graph APIs.\n- Boundary markers: No specific delimitation or instruction-ignoring markers are defined for data retrieved from external devices.\n- Capability inventory: The skill is capable of executing physical actions (e.g., controlling lights or thermostats) based on agent logic.\n- Sanitization: Data integrity relies on the connected third-party IoT services, with no additional sanitization described in the skill documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 7, 2026, 05:45 PM