Back to skill

Security audit

volcengine-rtc-device-control

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent device-control documentation, but it enables immediate hardware shutdown from natural-language intent without a confirmation step.

Review this before installing if the controlled device is important or shared. The main issue is not hidden malware, but that a user phrase like 'turn off the device' can become an immediate shutdown command without an explicit confirmation step in the skill instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The protocol defines an immediate power-off command with no confirmation, safety interlock, or user warning. Because shutdown is disruptive and potentially irreversible in the moment, an ambiguous or maliciously induced invocation could cause denial of service, interrupt active sessions, or terminate critical device functions without recourse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly supports a power_off action but does not warn that the command can immediately interrupt service or terminate an active session. In a device-control skill, omission of a confirmation or user-facing warning increases the chance of accidental shutdowns and abuse through ambiguous or misinterpreted natural-language requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill says it should be used whenever natural language implies device control and even allows custom command expansion, but it does not define strict trigger boundaries, authorization checks, or disambiguation rules. In a device-control context, broad activation increases the risk of unintended command generation from ambiguous phrasing, indirect prompt content, or mixed-topic conversations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The protocol exposes commands for emotion display and device vibration that are outside the stated manifest scope of common hardware controls. This scope drift increases the chance that an agent or integrator will invoke undocumented or unexpected behaviors, weakening least-privilege expectations and potentially enabling user-manipulative or unsafe physical actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language description and invocation examples are entirely in Chinese, which can imply a locale-specific interaction policy. Because the file does not state that the skill is intentionally limited to Chinese users or offer language flexibility, this may violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.