T09 · Insecure Skill Coding Practices
- Location
scripts/install-offline-bundle.sh:11- Finding
Offline bundles are extracted without integrity or archive-entry validation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This K10 PlatformIO skill is purpose-aligned, but its workshop installers and build setup can install or execute unchecked mutable code across user machines.
Review this skill before installing in a workshop. Use only trusted, freshly generated offline bundles, prefer pinned PlatformIO commits and hash-verified Python wheels, avoid bypassing macOS quarantine unless the installer source is verified, and tell users when examples activate camera, microphone, face recognition, or firmware flashing.
scripts/install-offline-bundle.sh:11Offline bundles are extracted without integrity or archive-entry validation
scripts/init-k10-platformio-project.sh:16PlatformIO builds use a mutable, unpinned Git dependency
scripts/prepare-macos-offline-installer.sh:102macOS offline installer downloads mutable Python packages without hash enforcement
The example instructs users to learn and recognize faces, which involves collecting and matching face identifiers, but the markdown provides no privacy or consent warning. Because this behavior can affect biometric privacy, the skill description should clearly disclose it to users.
The example describes wake-word-based speech recognition but omits a privacy warning that the device listens for spoken input and command phrases. Audio monitoring is privacy-sensitive behavior and should be explicitly disclosed in markdown descriptions.
The skill provides extensive shell and PowerShell commands, wrappers, and installer flows, but the metadata shown declares no explicit tool scope such as allowed-tools or permissions. In an agent setting, that mismatch can let the runtime or reviewers underestimate the skill's ability to cause filesystem, package-install, build, and upload side effects, increasing the chance of unintended command execution with broader access than expected.
This markdown example describes turning on the camera and detecting faces, but it does not warn users that the skill captures live camera imagery and processes biometric-like face data. For markdown files, camera or recognition behaviors that may affect privacy should be explicitly disclosed.
This example turns on the camera and performs live recognition, but the markdown does not warn that visual data from the environment is being captured and analyzed. Even though it targets animals, the camera may still observe people or private surroundings, so a user-facing disclosure is warranted.
The movement detection example uses the camera to monitor for motion, but the markdown gives no warning that nearby people or spaces may be observed. This is a privacy-relevant behavior that should be disclosed in the skill description for markdown files.
The description discusses QR code generation and storage requirements, but it does not clearly warn that the device camera will scan and decode visual content from the environment. Since this can capture incidental information in view, the markdown should disclose the behavior.
The example hard-codes CN_MODE and Chinese-language command phrases, which imposes a specific language setting without offering user choice. The policy allows locale constraints only when clearly documented and justified or when users can opt in, which is not done here.
This section explicitly limits the feature to Chinese firmware and uses only Chinese speech strings, but it does not present this as a user opt-in choice or offer alternatives. That creates a language/locale restriction that should be more clearly framed as a documented limitation or optional mode.
The document instructs users to remove macOS quarantine attributes from both the downloaded self-extracting installer and the extracted directory, which bypasses Gatekeeper protections that normally warn about untrusted downloaded code. In a workshop/USB distribution context, this increases the risk that tampered or substituted installer content will execute without OS scrutiny, especially since no explicit warning or integrity verification step is provided.
The upload command invokes pio run ... -t upload, which performs a write to attached hardware and can overwrite existing firmware. In this code path there is no confirmation prompt, warning message, or explanatory comment disclosing that a device write will occur.
This generated self-extracting .command script creates temporary directories, extracts an archive, creates parent directories, and moves the package into the default install location under $HOME/K10P. Although it prints informational messages during execution, it does not ask for confirmation before modifying the filesystem, and the generated script itself lacks a user-facing warning header or confirmation step for these writes.
The text states that TTS APIs exist only in the Chinese K10 firmware, which establishes a language-specific constraint in the skill guidance. While technically justified, this line does not explicitly frame the language/locale implication as a user choice or opt-in, so it can be read as steering users toward a specific language variant.
This section presents a Chinese-firmware TTS reference and the sample speaks a fixed Chinese phrase, which is a language-specific behavior. Because the documentation does not pair this with a user choice or note that the phrase is only an example, it risks violating the policy against forcing a specific language without opt-in.
The skill hard-codes Chinese utterances in its spoken output ("你好", "我是行空板", "语音合成") with no indication that the user can choose a language or that the skill is intentionally limited to a Chinese-only locale. This creates a natural-language locale policy concern because the skill enforces one language by default rather than offering opt-in or documenting the constraint.
The ASR initialization docs specify lang EN_MODE|CN_MODE, presenting a fixed language selection in the skill documentation without mentioning that the user should choose or consent to the locale. This can conflict with organizational language-choice policies because it normalizes hard-coded language behavior rather than user-driven selection.
The setup-platformio.command script creates a virtual environment and installs PlatformIO into it, which writes files under the bundle directory. While the script logs the root path and Python binary, it does not explicitly disclose before execution that it will create the penv directory and install packages there.
No suspicious patterns detected.