Back to skill

Security audit

onewo-rtlinux

Security checks for vulnerabilities and agentic risk

Overview

This Linux real-time programming skill is coherent, but it routinely tells users to run generated native code and system-wide tuning commands as root without enough scoping or rollback guidance.

Review before installing. Use this skill only on a dedicated test or real-time machine, not a shared or production workstation. Do not run generated binaries with `sudo` just because the skill says to; prefer unprivileged execution, capabilities, rtprio limits, or targeted device permissions after reviewing the generated C code. Treat GUI shutdown, IRQ affinity changes, and CPU governor writes as explicit administrative actions that need backups, rollback steps, and a clear reason.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:26
Finding

Mandatory Root Execution of Generated or User-Influenced Binaries

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:57
Finding

Mandatory Inclusion of Disruptive System-Wide Administrative Commands

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Chaining Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The pipeline echo performance | sudo tee $cpu combines unprivileged input with privileged file writes, a risky command pattern that normalizes privilege escalation through shell chaining. While the literal input here is fixed, the pattern is still dangerous in an agent skill because it encourages emitting shell constructs that can be easily generalized to unsafe privileged writes and makes review of side effects harder.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

[CONFIRM BEFORE RUNNING] Changes CPU frequency policy for all cores

cat /sys/devices/system/cpu/cpu*/cpufreq/scaling_governor for cpu in /sys/devices/system/cpu/cpu*/cpufreq/scaling_governor; do echo performance | sudo tee $cpu done

text
All cores especially isolated real-time cores must report performance governor mode.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill’s main output guidance instructs users to compile and run generated real-time code with sudo, but the surrounding guidance does not clearly foreground the risks of privileged execution. In this skill’s context, generated C code may interact with hardware, scheduling, affinity, and memory-mapped I/O, so encouraging routine root execution increases the chance of system instability or unsafe code being run with full privileges.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

The skill tells users to execute the produced binary with sudo as part of the default build-and-run flow. Because this assistant can generate or modify C code, normalizing privileged execution of its output creates a direct path for harmful or erroneous code to run with full system permissions.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

bash
gcc -O2 -o rt_task your_file.c -lrt -lpthread
sudo ./rt_task

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

The skill recommends sudo init 3, which immediately terminates the graphical session and changes system runlevel. Even though there is a brief confirmation note, this is still a disruptive privileged command embedded in routine environment guidance and can cause user data loss or service interruption if followed incautiously.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

Disable GUI

bash
# [CONFIRM BEFORE RUNNING] Immediately terminates graphical session
sudo init 3                                     # immediate

CPU Frequency Governor

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill includes a loop that writes performance to every CPU governor file using sudo tee, applying a system-wide privileged configuration change. This can affect thermals, power consumption, and system behavior across all cores, and the assistant presents it as standard setup rather than a narrowly justified, high-impact administrative action.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

[CONFIRM BEFORE RUNNING] Changes CPU frequency policy for all cores

cat /sys/devices/system/cpu/cpu*/cpufreq/scaling_governor for cpu in /sys/devices/system/cpu/cpu*/cpufreq/scaling_governor; do echo performance | sudo tee $cpu done

text
All cores especially isolated real-time cores must report performance governor mode.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The kernel-module and IRQ-affinity guidance discusses request_threaded_irq, ioremap, and binding interrupts to isolated cores without a strong warning that these actions can affect system stability, hang devices, or disrupt interrupt routing. In a Linux RT skill, this is more dangerous than generic systems advice because users are being guided toward low-level kernel and interrupt manipulation where mistakes can degrade or crash the host.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.