Back to skill

Security audit

Unihiker K10 Ota

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent OTA update guide, but its examples create an unauthenticated HTTP firmware update path with default Wi-Fi credentials, so it should be reviewed before use.

Install only if you understand that the provided OTA pattern can let anyone with network access to the K10 OTA endpoint replace the device firmware. Before using it on a real network, add per-device authentication, avoid shared default AP passwords, keep OTA mode temporary and locally triggered, and prefer signed firmware or equivalent integrity checks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
references/ota-implementation.md:279
Finding

Unauthenticated Plaintext HTTP OTA Permits Arbitrary Firmware Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

Step 1: Add Custom Partition Table

Create partitions.csv in your sketch directory:

csv
# K10 OTA partition table that preserves speech-recognition model regions.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The OTA examples expose a plain HTTP POST /ota firmware upload path with no authentication, authorization, integrity verification, or warning that anyone on the reachable network could replace device firmware. In context, this is especially dangerous because firmware upload gives code-execution persistence on the device, turning a nearby or same-network attacker into a full device compromiser.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/ota-implementation.md (reported line 53)May include surrounding context.

coredump, data, coredump,, 1K,

text

**Problem:** There is no `ota_0` / `ota_1` / `otadata` partition. `Update.begin()` fails immediately because it cannot find an inactive OTA slot to write to.

**Solution for K10 AI projects:** Create `partitions.csv` in your sketch directory with OTA partitions that stop before the model region:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The maintenance-mode example enables a writable OTA access point with a predictable SSID and a weak default password, while omitting a clear warning that anyone who joins that AP may be able to flash arbitrary firmware. Because firmware updates imply code execution persistence, this is effectively an unsafe remote administration interface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide instructs users to expose a firmware upload endpoint over plain HTTP and POST arbitrary firmware to it, but it does not prominently warn that this allows anyone with network access to push code that rewrites device flash. In the context of OTA, lack of authentication, transport protection, and explicit security guidance can lead directly to unauthorized firmware installation and full device compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The statement describes speech synthesis as available only in Chinese firmware and unavailable in English/international firmware, which is a natural-language locale restriction. As written, it does not offer user opt-in/choice or explain a policy or compliance justification for the limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.