Back to skill

Security audit

Ai-Thinker-Coder

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only IoT hardware development skill with disclosed setup, install, SDK clone, build, USB passthrough, and firmware flashing guidance.

Before using the skill, verify repository URLs before cloning SDKs, inspect any cloned SDK scripts before running builds, and confirm the target serial device before usbipd binding or firmware flashing because those commands can affect connected hardware.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.