Back to skill

Security audit

MM IoT SDK Hardware Bringup

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Markdown-only hardware bring-up guide with no hidden agent-control behavior or executable installer.

Install only if you want the agent to help with mm-iot-sdk porting and embedded hardware debugging. Review generated build, flash, OpenOCD, or GDB commands before running them on real boards because those actions can change device firmware or hardware state.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
### GPIO pins

| Pin       | Direction            | Edge / Level | Notes                                                                                |
|-----------|----------------------|--------------|--------------------------------------------------------------------------------------|
| BUSY      | Transceiver → Host   | Rising edge  | Prevents host from sleeping. Configure as input with rising-edge interrupt.          |
| WAKE      | Host → Transceiver   | Output       | Prevents transceiver sleeping. Hold HIGH permanently until power-optimisation phase. |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

md
Reference shims live at:
`mm-iot-sdk/framework/src/platforms/*/mm_shims/mmhal_wlan.c`

| Parameter         | Requirement                                                                                       |
|-------------------|---------------------------------------------------------------------------------------------------|
| Role              | Host is SPI master; transceiver is slave.                                                         |
| Mode              | Mode 0 only: CPOL=0, CPHA=0.                                                                      |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 259)May include surrounding context.

md
|-------------------|---------------------------------------------------------------------------------------------------|
| Role              | Host is SPI master; transceiver is slave.                                                         |
| Mode              | Mode 0 only: CPOL=0, CPHA=0.                                                                      |
| Bit order         | MSB first.                                                                                        |
| Frame size        | 8-bit.                                                                                            |
| Duplex            | Half-duplex protocol over full-duplex pins (both MISO and MOSI must be wired).                    |
| Clock frequency   | 20 MHz is a safe starting point; some platforms reach 40 MHz. See transceiver datasheet for max.  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 260)May include surrounding context.

md
| Role              | Host is SPI master; transceiver is slave.                                                         |
| Mode              | Mode 0 only: CPOL=0, CPHA=0.                                                                      |
| Bit order         | MSB first.                                                                                        |
| Frame size        | 8-bit.                                                                                            |
| Duplex            | Half-duplex protocol over full-duplex pins (both MISO and MOSI must be wired).                    |
| Clock frequency   | 20 MHz is a safe starting point; some platforms reach 40 MHz. See transceiver datasheet for max.  |
| Chip select       | Software-controlled GPIO — do not use the SPI peripheral's hardware NSS.                          |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
Reference shims live at:
`mm-iot-sdk/framework/src/platforms/*-sdio/mm_shims/mmhal_wlan.c`

| Parameter        | Requirement                                                                                      |
|------------------|--------------------------------------------------------------------------------------------------|
| Role             | Host is SDIO controller; transceiver is SDIO card.                                               |
| Bus width        | 4-bit (enable `ENABLE_SDIO_4BIT`). 1-bit is supported as fallback only.                         |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 290)May include surrounding context.

md
| Bus width        | 4-bit (enable `ENABLE_SDIO_4BIT`). 1-bit is supported as fallback only.                         |
| Init clock       | 400 kHz during card enumeration (`SD_INIT_FREQ_HZ`).                                            |
| DMA              | Internal DMA (IDMA, single-buffer mode) required. Buffers 32-bit aligned, length multiple of 4. |
| Write timeout    | 750 ms.                                                                                          |
| Read timeout     | 1000 ms.                                                                                         |
| IRQ delivery     | In-band via DAT1 (`SDMMC` peripheral delivers `SDIO_IT_SDIOIT`). No separate IRQ GPIO needed.   |
| BUSY GPIO        | Still required as a separate GPIO even with SDIO — BUSY is not carried in-band.                  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 291)May include surrounding context.

md
| Init clock       | 400 kHz during card enumeration (`SD_INIT_FREQ_HZ`).                                            |
| DMA              | Internal DMA (IDMA, single-buffer mode) required. Buffers 32-bit aligned, length multiple of 4. |
| Write timeout    | 750 ms.                                                                                          |
| Read timeout     | 1000 ms.                                                                                         |
| IRQ delivery     | In-band via DAT1 (`SDMMC` peripheral delivers `SDIO_IT_SDIOIT`). No separate IRQ GPIO needed.   |
| BUSY GPIO        | Still required as a separate GPIO even with SDIO — BUSY is not carried in-band.                  |

Static analysis

No suspicious patterns detected.