ha-configuration

Pass

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents standard Home Assistant administrative commands (e.g., docker exec, ha core check, hass script) for validating and optimizing configurations.- [EXTERNAL_DOWNLOADS]: Includes an example of a REST sensor that fetches repository data from the official GitHub API, which is a well-known and trusted service.- [PROMPT_INJECTION]: The skill facilitates the creation of a surface for indirect prompt injection via external data ingestion. 1. Ingestion points: External REST API resources and MQTT topics defined in configuration examples. 2. Boundary markers: No delimiters or explicit instructions to ignore embedded commands are included in the configuration patterns. 3. Capability inventory: The skill uses tools with file system write access (Edit, Write, TodoWrite) and searching capabilities (Grep). 4. Sanitization: No specific input validation or sanitization logic is demonstrated for the templates processing the ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 27, 2026, 07:20 PM