Back to skill

Security audit

Rdk X5 Network

Security checks for vulnerabilities and agentic risk

Overview

This network setup skill is mostly purpose-aligned, but it includes risky copy-paste commands for remote access and hotspot setup without enough safety guidance.

Install only if you are comfortable with privileged network administration on an RDK X5. Replace the hotspot password with a strong unique value, avoid enabling SSH/VNC persistently unless you need it, restrict remote access to trusted networks, and be careful not to delete or modify the connection currently keeping your session alive.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Warning
Location
SKILL.md:80
Finding

SSH Service Is Persistently Enabled Without Explicit Confirmation or Hardening

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 80
Vulnerability Type: Persistent startup service and unnecessary long-term network exposure
Risk Level: Medium

Complete Code Snippet:

bash
# SSH enablement
sudo systemctl enable ssh && sudo systemctl start ssh

Technical Analysis

The command performs two distinct operations with elevated privileges:

  1. systemctl start ssh starts the SSH service for the current system session.
  2. systemctl enable ssh modifies startup configuration so that SSH is automatically launched on subsequent boots.

Starting SSH is consistent with the Skill's declared remote-access functionality. However, automatically enabling it across reboots creates persistent network exposure beyond what is required for a temporary remote-access request. The instruction does not require explicit user confirmation for persistence and does not first assess authentication policy, root login, password authentication, listening interfaces, or firewall restrictions.

This does not establish that the Skill intentionally installs a backdoor. Nevertheless, it creates a persistent service that may be reachable by untrusted networks and therefore exceeds minimum privilege and exposure requirements when only temporary SSH access is needed.

Attack Path

  1. A user follows the documented command to obtain SSH access.
  2. The command enables SSH at boot as root and immediately starts the service.
  3. SSH remains available after reboots, even if the user intended only temporary access.
  4. A network-adjacent or Internet-based attacker discovers the exposed SSH port.
  5. The attacker attempts credential guessing or exploits any independently vulnerable SSH configuration.
  6. If authentication is compromised, the attacker obtains the permissions of the affected SSH account and may subsequently attempt local privilege escalation.

Impact Assessment

The immediate impact is ...[truncated 606 chars]

Remediation
View remediation

Remediation Suggestions

  • Use sudo systemctl start ssh for temporary access by default.
  • Require explicit user confirmation before running sudo systemctl enable ssh.
  • Clearly explain that enable persists across reboots.
  • Provide a rollback command:
    bash
    sudo systemctl disable --now ssh
    
  • Require key-based authentication and disable password authentication where practical.
  • Disable direct root login by setting PermitRootLogin no.
  • Restrict SSH to trusted interfaces, source addresses, or management networks through firewall rules.
  • Verify configuration with sshd -T and service exposure with ss -lntp.
  • Instruct users to stop or disable SSH after remote maintenance is complete.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:38
Finding

Predictable Hardcoded Wi-Fi Hotspot Password in Executable Example

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 38
Vulnerability Type: Predictable hardcoded wireless credential
Risk Level: High

Complete Code Snippet:

bash
sudo nmcli device wifi hotspot ifname wlan0 ssid "RDK-X5-AP" password "12345678"

Technical Analysis

The hotspot command contains the literal password 12345678, which is a predictable minimum-length example credential. Because the command is presented as directly executable rather than as a clearly marked placeholder, users may copy it without modification.

The password is publicly documented and trivial to guess. Any nearby party who observes the RDK-X5-AP network can try the documented credential. Although the password is not a secret embedded for access to an existing system, using it unchanged creates an insecure wireless configuration and undermines the hotspot's authentication boundary.

Attack Path

  1. A user copies and executes the documented hotspot command without changing the password.
  2. The device advertises the recognizable RDK-X5-AP SSID.
  3. A nearby attacker identifies the wireless network.
  4. The attacker authenticates using the documented password 12345678.
  5. The attacker receives network connectivity through the hotspot.
  6. The attacker probes the hotspot gateway and connected clients for exposed services, including SSH, VNC, administrative interfaces, and other local services.
  7. Any independently vulnerable or weakly authenticated local service may then be targeted.

Impact Assessment

Successful use of the known password grants unauthorized network-level access to the hotspot. This can permit bandwidth consumption, probing of the host and connected clients, access to services bound to the hotspot interface, and use of the device's upstream connection where forwarding is enabled.

The hotspot password alone does not grant operating-system privileges. Additional compromise depends on the ava ...[truncated 200 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the literal password with an unmistakable placeholder:
    bash
    sudo nmcli device wifi hotspot ifname wlan0 ssid "RDK-X5-AP" password "<STRONG_UNIQUE_PASSWORD>"
    
  • Explicitly warn users not to copy example credentials unchanged.
  • Require a unique randomly generated password of sufficient length.
  • Consider generating a password locally, for example:
    bash
    openssl rand -base64 18
    
  • Avoid exposing sensitive management services to the hotspot interface unless required.
  • Apply host firewall rules that restrict hotspot clients to only the services they need.
  • Instruct users to stop the hotspot when it is no longer needed:
    bash
    sudo nmcli connection down Hotspot
    
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (20)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

bash
# SSH 开启
sudo systemctl enable ssh && sudo systemctl start ssh

# VNC 开启(通过 srpi-config)
sudo srpi-config

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

bash
# 连接(替换 SSID 和 PASSWORD)
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

bash
# 连接(替换 SSID 和 PASSWORD)
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

bash
# 连接(替换 SSID 和 PASSWORD)
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

bash
# 连接(替换 SSID 和 PASSWORD)
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

bash
# 连接(替换 SSID 和 PASSWORD)
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

bash
# 连接(替换 SSID 和 PASSWORD)
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

bash
# 连接(替换 SSID 和 PASSWORD)
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

bash
# 连接(替换 SSID 和 PASSWORD)
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

bash
# 连接(替换 SSID 和 PASSWORD)
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

bash
# 连接(替换 SSID 和 PASSWORD)
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

bash
# 连接(替换 SSID 和 PASSWORD)
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

# 查看 / 删除已保存连接
nmcli connection show

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

# 查看 / 删除已保存连接
nmcli connection show

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

# 查看 / 删除已保存连接
nmcli connection show

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
sudo nmcli device wifi connect "SSID" password "PASSWORD"

# 连接隐藏 WiFi
sudo nmcli device wifi connect "SSID" password "PASSWORD" hidden yes

# 查看 / 删除已保存连接
nmcli connection show

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill includes commands to delete saved network connections without warning that the active or fallback network profile may be removed. This can disrupt connectivity and may lock a user out of a remote system, especially if they are administering the device over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs users to enable SSH and VNC remote access without warning that these services expose remote management interfaces and can increase attack surface. On a device connected to untrusted networks, enabling them may permit unauthorized access if authentication, firewalling, or network exposure are not properly controlled.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

systemctl enable ssh makes the SSH service persist across reboots, extending the duration of remote attack surface beyond the immediate troubleshooting session. Without warning or compensating controls, this can leave unnecessary remote access enabled long-term on devices that may be exposed to local or wider networks.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

bash
# SSH 开启
sudo systemctl enable ssh && sudo systemctl start ssh

# VNC 开启(通过 srpi-config)
sudo srpi-config

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata explicitly says it should not be used for GPIO/hardware tasks, but the documented srpi-config scope includes 40-pin bus and MIPI screen configuration. This creates scope confusion that can lead the agent or user into making hardware-related changes outside the declared boundaries, increasing the chance of unintended or unsafe system modifications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.