AI called this Suspicious at 91.0% confidence as Dangerous Capability with low false-positive risk.
Evidence for warning
- Runtime MCP server reads HA, ESPHome, Node-RED, and VomeHome credentials from environment.
- Registered tools can control HA services and edit/delete automation and Node-RED configuration.
- ESPHome tools can request remote validate/compile/upload commands.
Evidence against
- package.json has only a prepare build hook; no preinstall/install/postinstall payload.
- Network clients send credentials only to configured service URLs or the documented VomeHome API.
- Write/configuration actions are gated by explicit safety flags in direct mode.
- No child_process, eval/vm, local credential harvesting, persistence, or foreign agent-config writes found.
Behavioral surface
SourceEnvironmentVarsFilesystemNetworkWebSocket
Supply chainHighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 26 file(s), 124 KB of source, external domains: homeassistant.local, vome.io