hass-config-flow

Warn

Audited by Snyk on Feb 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The prompt explicitly instructs running privileged commands (e.g., "sudo python3 -c ...", "sudo bash ha-token.sh") to read /var/lib/hass/.storage/auth and generate tokens, which requests elevated privileges and can compromise the machine's state and credentials.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 23, 2026, 10:03 PM