Back to skill

Security audit

OMA LwM2M Expert

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only LwM2M protocol reference skill with broad activation wording but no evidence of code execution, credential access, persistence, or hidden data handling.

Install if you want a broad LwM2M/IoT protocol assistant, but expect it may activate for some adjacent IoT questions where another skill could be more appropriate. For production security or standards decisions, verify critical details against current OMA, IETF, GSMA, and vendor documentation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list is extremely expansive and includes adjacent ecosystem terms that can appear in many general IoT discussions, increasing the chance this skill is invoked when the user did not actually ask for LwM2M-specific expertise. Over-broad activation can cause misrouting to a highly specialized skill, producing irrelevant or overconfident protocol guidance and crowding out better-matched skills.

Vague Triggers

High
Confidence
97% confidence
Finding
This instruction explicitly tells the system to trigger on generic phrases like 'device management' or 'IoT protocol' even when 'LwM2M' is not mentioned, with only loose contextual checks. That creates a strong risk of unintended invocation across broad IoT/security/networking conversations, leading to incorrect specialization, poor task routing, and potentially unsafe advice if the model forces LwM2M assumptions onto unrelated protocols or environments.

Static analysis

No suspicious patterns detected.