Microsoft Copilot security directory

myStrom (Independent Publisher)

Published by Tomasz Poszytek

High risk

myStrom is a Swiss company producing smart home devices. With this connector it is possible to control myStrom devices over the REST API.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Can execute code or queries: This connector can run arbitrary queries or code against a database or execution engine. An AI-generated query could be manipulated to exfiltrate, corrupt, or destroy data.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 9 tools or capabilities.

  • Authentication
  • Create webhook
  • Delete webhook
  • Execute scene
  • Get device
  • Get devices
  • Get scenes
  • Get webhook
  • Toggle device

The interactive security report will load automatically.