Back to skill

Security audit

UNIHIKER K10 PlatformIO

Security checks for vulnerabilities and agentic risk

Overview

This K10 PlatformIO skill is purpose-aligned, but its workshop installers and build setup can install or execute unchecked mutable code across user machines.

Review this skill before installing in a workshop. Use only trusted, freshly generated offline bundles, prefer pinned PlatformIO commits and hash-verified Python wheels, avoid bypassing macOS quarantine unless the installer source is verified, and tell users when examples activate camera, microphone, face recognition, or firmware flashing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/install-offline-bundle.sh:11
Finding

Offline bundles are extracted without integrity or archive-entry validation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/init-k10-platformio-project.sh:16
Finding

PlatformIO builds use a mutable, unpinned Git dependency

Content
View full analysis
"$PROJECT_DIR/platformio.ini" <<'EOF' [env:unihiker] platform = https://github.com/DFRobot/platform-unihiker.git board = unihiker_k10 framework = arduino build_flags = -DARDUINO_USB_CDC_ON_BOOT=1 -DARDUINO_USB_MODE=1 -DModel=None monitor_speed = 115200 EOF fi ``` `examples/tts-buttons/platformio.ini:1-8`: ```ini [env:unihiker] platform = https://github.com/DFRobot/platform-unihiker.git board = unihiker_k10 framework = arduino build_flags = -DARDUINO_USB_CDC_ON_BOOT=1 -DARDUINO_USB_MODE=1 -DModel=None ``` The generated macOS and Windows example projects use the same mutable dependency: ```ini platform = https://github.com/DFRobot/platform-unihiker.git ``` ### Technical Analysis The active project templates reference the current state of a Git repository instead of an audited commit or immutable release artifact. PlatformIO platform packages contain executable build logic and package metadata. Consequently, code obtained from this dependency can execute on the build host and can select additional frameworks or toolchain packages. The repository includes an example of pinning to commit `508e31875ad92205bf946e28570fb78fc01ceb2e` in `references/platformio-workshop.md:171-174`, but pinning is only presented as optional guidance. The actual templates, bundled example configurations, and primary documentation continue to use the mutable URL. This makes the effective build behavior changeable after the Skill ...[truncated 1321 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/prepare-macos-offline-installer.sh:102
Finding

macOS offline installer downloads mutable Python packages without hash enforcement

Content
View full analysis
=4.10.0" if ! find "$ROOT/wheelhouse" -maxdepth 1 -type f -iname 'typing_extensions-*.whl' | grep -q .; then echo "[ERROR] Failed to add typing-extensions to the offline wheelhouse." >&2 echo "This wheel is required when student Macs use Python older than 3.13." >&2 exit 1 fi ``` Generated student installation logic at `scripts/prepare-macos-offline-installer.sh:165-174`: ```bash if [[ ! -d "$ROOT/penv" ]]; then "$PYTHON_BIN" -m venv "$ROOT/penv" fi "$ROOT/penv/bin/python" -m pip install --no-index --find-links "$ROOT/wheelhouse" platformio export PLATFORMIO_CORE_DIR="$ROOT/.platformio" "$ROOT/penv/bin/python" -m platformio --version ``` ### Technical Analysis The packaging script downloads the latest resolvable `platformio` release, its transitive dependencies, and any `typing-extensions` version at or above 4.10.0. No exact version lock, hash-locked requirements file, repository snapshot, or signed manifest is used. Although student installation uses `--no-index`, this only prevents network access at installation time. It does not establish that the wheels downloaded on the teacher machine are trusted or reproducible. Whatever packages were resolved during preparation are copied into the installer and installed on every recipient system. The resulting Python environment is immediately used to execute PlatformIO. Therefore, mali ...[truncated 1246 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (17)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example instructs users to learn and recognize faces, which involves collecting and matching face identifiers, but the markdown provides no privacy or consent warning. Because this behavior can affect biometric privacy, the skill description should clearly disclose it to users.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example describes wake-word-based speech recognition but omits a privacy warning that the device listens for spoken input and command phrases. Audio monitoring is privacy-sensitive behavior and should be explicitly disclosed in markdown descriptions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill provides extensive shell and PowerShell commands, wrappers, and installer flows, but the metadata shown declares no explicit tool scope such as allowed-tools or permissions. In an agent setting, that mismatch can let the runtime or reviewers underestimate the skill's ability to cause filesystem, package-install, build, and upload side effects, increasing the chance of unintended command execution with broader access than expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown example describes turning on the camera and detecting faces, but it does not warn users that the skill captures live camera imagery and processes biometric-like face data. For markdown files, camera or recognition behaviors that may affect privacy should be explicitly disclosed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

This example turns on the camera and performs live recognition, but the markdown does not warn that visual data from the environment is being captured and analyzed. Even though it targets animals, the camera may still observe people or private surroundings, so a user-facing disclosure is warranted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The movement detection example uses the camera to monitor for motion, but the markdown gives no warning that nearby people or spaces may be observed. This is a privacy-relevant behavior that should be disclosed in the skill description for markdown files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description discusses QR code generation and storage requirements, but it does not clearly warn that the device camera will scan and decode visual content from the environment. Since this can capture incidental information in view, the markdown should disclose the behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example hard-codes CN_MODE and Chinese-language command phrases, which imposes a specific language setting without offering user choice. The policy allows locale constraints only when clearly documented and justified or when users can opt in, which is not done here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This section explicitly limits the feature to Chinese firmware and uses only Chinese speech strings, but it does not present this as a user opt-in choice or offer alternatives. That creates a language/locale restriction that should be more clearly framed as a documented limitation or optional mode.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs users to remove macOS quarantine attributes from both the downloaded self-extracting installer and the extracted directory, which bypasses Gatekeeper protections that normally warn about untrusted downloaded code. In a workshop/USB distribution context, this increases the risk that tampered or substituted installer content will execute without OS scrutiny, especially since no explicit warning or integrity verification step is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The upload command invokes pio run ... -t upload, which performs a write to attached hardware and can overwrite existing firmware. In this code path there is no confirmation prompt, warning message, or explanatory comment disclosing that a device write will occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This generated self-extracting .command script creates temporary directories, extracts an archive, creates parent directories, and moves the package into the default install location under $HOME/K10P. Although it prints informational messages during execution, it does not ask for confirmation before modifying the filesystem, and the generated script itself lacks a user-facing warning header or confirmation step for these writes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The text states that TTS APIs exist only in the Chinese K10 firmware, which establishes a language-specific constraint in the skill guidance. While technically justified, this line does not explicitly frame the language/locale implication as a user choice or opt-in, so it can be read as steering users toward a specific language variant.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This section presents a Chinese-firmware TTS reference and the sample speaks a fixed Chinese phrase, which is a language-specific behavior. Because the documentation does not pair this with a user choice or note that the phrase is only an example, it risks violating the policy against forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill hard-codes Chinese utterances in its spoken output ("你好", "我是行空板", "语音合成") with no indication that the user can choose a language or that the skill is intentionally limited to a Chinese-only locale. This creates a natural-language locale policy concern because the skill enforces one language by default rather than offering opt-in or documenting the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The ASR initialization docs specify lang EN_MODE|CN_MODE, presenting a fixed language selection in the skill documentation without mentioning that the user should choose or consent to the locale. This can conflict with organizational language-choice policies because it normalizes hard-coded language behavior rather than user-driven selection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The setup-platformio.command script creates a virtual environment and installs PlatformIO into it, which writes files under the bundle directory. While the script logs the root path and Python binary, it does not explicitly disclose before execution that it will create the penv directory and install packages there.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.