Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill exposes high-impact physical control actions, including `lutron_all_off`, scene activation, cover control, and button tap simulation, without any built-in confirmation, warning, or policy gating for destructive or disruptive operations. In an agent setting, a mistaken model action, prompt injection from upstream content, or ambiguous user request could immediately turn off devices across a home or manipulate occupancy-related behavior, causing safety, availability, or privacy issues.
