Back to skill

Security audit

raspberry-pi-servo

Security checks for vulnerabilities and agentic risk

Overview

The skill matches Raspberry Pi servo control, but it includes privileged hardware and boot-configuration steps that need review before use.

Review this skill before installing or following its commands. Only use it on a Raspberry Pi where you understand the attached servo and PWM mapping, avoid the infinite test loop as written, confirm safe pulse-width limits, keep hands and mechanisms clear, and back up boot configuration before changing PWM or audio settings.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:58
Finding

Unpinned Third-Party Python Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 58-62
Vulnerability Type: Unpinned dependency installation
Risk Level: Medium

bash
2. 执行 pip 安装命令

    ```bash
    pip install rpi-hardware-pwm
    ```

Technical Analysis

The installation command retrieves rpi-hardware-pwm without specifying a reviewed version or verifying an integrity hash. Consequently, the package version and effective code installed can change over time without any corresponding change to this skill.

Python package installation can execute package build hooks and subsequently exposes the installed package to execution when it is imported. If the package distribution or its publishing account is compromised, a modified release could execute attacker-controlled code with the privileges of the user running pip or the servo-control program. The absence of a lock file, hashes, and an explicitly documented trusted source also makes installations non-reproducible.

Attack Path

  1. An attacker compromises the upstream package, its publisher account, or its distribution process.
  2. The attacker publishes a malicious release under the expected package name.
  3. A user follows the skill instruction and runs pip install rpi-hardware-pwm.
  4. Because no version or hash is enforced, pip resolves and downloads the attacker-controlled release.
  5. Malicious code may execute through installation hooks or when the installed package is imported by the PWM example.
  6. The payload obtains the permissions available to the invoking user and can access resources available within that user's environment.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the user performing the installation or running the imported package. This may expose that user's files, environment variables, network access, and hardware interfaces for which the user has permission. The documented command ...[truncated 106 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin rpi-hardware-pwm to a specifically reviewed version.
  • Maintain the dependency in a lock or requirements file containing cryptographic hashes.
  • Install with hash enforcement, such as pip install --require-hashes -r requirements.txt.
  • Document the expected official package index and upstream source repository.
  • Review direct and transitive dependencies before updating the pinned version.
  • Prefer binary wheels from a trusted source where appropriate, and prevent unexpected source builds.
  • Continue installing into an isolated virtual environment with the least-privileged user required for operation.

T09 · Insecure Skill Coding Practices

Error
Location
references/troubleshooting.md:48
Finding

Unbounded Privileged Servo Actuation Loop

Content
View full analysis

Vulnerability Details

File Location: references/troubleshooting.md, lines 48-58
Vulnerability Type: Unsafe privileged hardware-control procedure
Risk Level: High

bash
# 导出PWM
echo 0 | sudo tee /sys/class/pwm/pwmchip2/export

# 设置周期
echo 20000000 | sudo tee /sys/class/pwm/pwmchip2/pwm0/period

# 循环摆动
while true; do
    echo 500000 | sudo tee /sys/class/pwm/pwmchip2/pwm0/duty_cycle   # 0度
    sleep 1
    echo 2500000 | sudo tee /sys/class/pwm/pwmchip2/pwm0/duty_cycle  # 180度
    sleep 1
done

Technical Analysis

The troubleshooting procedure exports a hardcoded PWM channel and repeatedly writes endpoint duty-cycle values through privileged sysfs operations. The while true loop has no iteration limit, explicit user confirmation, hardware identity validation, safe shutdown handler, or automatic PWM disable operation.

The same troubleshooting document notes that PWM chip indices on Raspberry Pi 5 are not fixed. Therefore, hardcoding pwmchip2/pwm0 without validating the detected controller increases the risk of targeting an unintended PWM interface. The example also assumes that pulse widths of 500,000 and 2,500,000 nanoseconds are safe for the connected servo, although supported ranges can vary.

Interrupting the loop does not explicitly set a neutral duty cycle, disable PWM, or unexport the channel. Depending on device behavior, the last configured output may therefore remain active after interruption.

Attack Path

  1. A user encounters a servo-control problem and follows the minimal troubleshooting example.
  2. The user authorizes the sudo tee operations, allowing writes to the selected PWM sysfs interface.
  3. The example exports hardcoded channel pwmchip2/pwm0 without first confirming that it corresponds to the intended pin and servo.
  4. The infinite loop alternates the configured output between the two endpoint pulse widths once per second.
  5. The servo continues traversi ...[truncated 1075 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the infinite loop with a small, explicit number of test cycles.
  • Require affirmative user confirmation immediately before physical actuation.
  • Detect and validate the correct PWM controller, channel, GPIO mapping, and current channel state instead of hardcoding pwmchip2/pwm0.
  • Ask the user to disconnect the mechanical load or establish a safe movement area before testing.
  • Require the pulse-width limits from the servo manufacturer rather than assuming that 500–2,500 microseconds is universally safe.
  • Begin at a verified neutral position and increase the movement range gradually.
  • Add shell signal handling that disables PWM and unexports the channel on normal exit, interruption, or error.
  • Abort if exporting the channel or configuring the period fails; do not continue after partial configuration.
  • Warn users about independent servo power requirements, common grounding, and current capacity.
  • Avoid privileged writes until all device-selection and safety checks have completed successfully.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/troubleshooting.md (reported line 49)May include surrounding context.

bash
# 导出PWM
echo 0 | sudo tee /sys/class/pwm/pwmchip2/export

# 设置周期
echo 20000000 | sudo tee /sys/class/pwm/pwmchip2/pwm0/period

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/troubleshooting.md (reported line 52)May include surrounding context.

bash
# 导出PWM
echo 0 | sudo tee /sys/class/pwm/pwmchip2/export

# 设置周期
echo 20000000 | sudo tee /sys/class/pwm/pwmchip2/pwm0/period

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/troubleshooting.md (reported line 56)May include surrounding context.

bash
# 导出PWM
echo 0 | sudo tee /sys/class/pwm/pwmchip2/export

# 设置周期
echo 20000000 | sudo tee /sys/class/pwm/pwmchip2/pwm0/period

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/troubleshooting.md (reported line 58)May include surrounding context.

bash
# 导出PWM
echo 0 | sudo tee /sys/class/pwm/pwmchip2/export

# 设置周期
echo 20000000 | sudo tee /sys/class/pwm/pwmchip2/pwm0/period

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger text is broad enough that an agent could invoke this skill whenever a task mentions servo control, without clear limits on when it may inspect hardware state, suggest system changes, or initiate setup steps. In this skill, that ambiguity matters because the instructions include checking kernel modules, editing boot configuration, installing packages, and requesting a reboot, which increases the chance of unnecessary or premature system-level actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
72% confidence
Finding

The skill metadata and all user-facing instructions are written entirely in Chinese, with no indication that the user can choose another language or that the locale restriction is intentional and justified. This may violate a language/locale policy if skills are expected not to force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document instructs users to disable onboard audio by editing boot configuration, which changes system behavior beyond the immediate troubleshooting session. While not inherently malicious, presenting this as a direct fix without clear warnings about side effects, backup guidance, or rollback steps can lead users to unnecessarily weaken or disrupt their system configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The minimal test contains an infinite loop that continuously drives the servo between extreme duty cycles using privileged writes, but it gives no warning about unexpected physical movement, power draw, overheating, or how to stop safely. In a hardware-control skill, this can cause equipment damage or user injury if copied blindly.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 49)May include surrounding context.

bash
# 导出PWM
echo 0 | sudo tee /sys/class/pwm/pwmchip2/export

# 设置周期
echo 20000000 | sudo tee /sys/class/pwm/pwmchip2/pwm0/period

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 58)May include surrounding context.

bash
# 导出PWM
echo 0 | sudo tee /sys/class/pwm/pwmchip2/export

# 设置周期
echo 20000000 | sudo tee /sys/class/pwm/pwmchip2/pwm0/period

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 52)May include surrounding context.

md
echo 0 | sudo tee /sys/class/pwm/pwmchip2/export

# 设置周期
echo 20000000 | sudo tee /sys/class/pwm/pwmchip2/pwm0/period

# 循环摆动
while true; do

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 56)May include surrounding context.

md
echo 0 | sudo tee /sys/class/pwm/pwmchip2/export

# 设置周期
echo 20000000 | sudo tee /sys/class/pwm/pwmchip2/pwm0/period

# 循环摆动
while true; do

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The entire skill document is presented in Chinese and does not indicate that the language is optional, user-selected, or justified by a region-specific requirement. The policy calls for flagging language or locale constraints when a specific language is effectively forced without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.