xiaomi-home-skill

clawhub:xiaomi-home-skill

View source
B
85/100

First Seen

Feb 18, 2026

Last Scanned

Feb 22, 2026

Findings

1

Score

85/100

HIGH 1

Findings (1)

HIGH
Shell metacharacters in MCP config args
L4

Detects shell metacharacters (pipes, backticks, subshells) in MCP server command arguments

"command":"pipx install python-miio && /Users/$(
FIX

Remove credentials (API keys, tokens, passwords) from MCP server configuration. Use environment variable references (e.g., ${API_KEY}) or a secrets manager instead of inline values.

FP?

Likely FP if the credential value is a placeholder (e.g., your-api-key-here, sk_test_xxx) in example configuration.