Carrera HYBRID BLE Controller

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed BLE controller for Carrera HYBRID RC cars, with expected physical-control and protocol-analysis risks that users should handle carefully.

Install only if you intend to control your own Carrera HYBRID/Sturmkind RC car. Verify the BLE address, supervise the car while commands run, keep any Telegram bot restricted to trusted chat IDs, and use MITM/protocol sniffing only on devices and traffic you own or are authorized to analyze.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises MITM proxying and Telegram-based remote control without prominent warnings about authorization, privacy, and operational risk. In this context, those features could facilitate interception of BLE traffic or unattended remote actuation of physical devices, increasing the chance of misuse or unsafe deployment.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal