Back to skill

Security audit

led controler

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-built to control Raspberry Pi GPIO pins, but it sends unauthenticated plaintext hardware commands and does not locally enforce the documented action or pin limits.

Review before installing. Use this only on a trusted, isolated network with a Pi server that independently authenticates requests, enforces an action and pin allowlist, rejects malformed JSON, and runs with least GPIO privilege. Treat connected hardware as the real risk: relays, actuators, or other devices may be switched if the endpoint is reachable or traffic is modified.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.sh:6
Finding

Unrestricted Remote Action Forwarding

Content
View full analysis
| gpio_off " # exit 1 代表程式異常終止(回傳非 0 值) exit 1 fi ``` ```bash curl -s http://$PI_IP:9000/run \ -H "Content-Type: application/json" \ -d "{\"action\": \"$ACTION\", \"pin\": $PIN}" ``` ### Technical Analysis The documented interface permits only `gpio_on` and `gpio_off`, but the script verifies only that `ACTION` is nonempty. It then forwards the value unchanged to the remote `/run` endpoint. The claim in `SKILL.md` that the Pi server restricts actions cannot be verified because the server implementation is not included in the audited project. Consequently, the client relies entirely on an external security control instead of enforcing the documented action boundary locally. ### Attack Path 1. An attacker or agent capable of invoking `scripts/main.sh` supplies an undocumented action: ```bash ./scripts/main.sh undocumented_action 17 ``` 2. The script accepts the nonempty action without checking it against an allowlist. 3. It sends the following request to the Pi: ```json {"action": "undocumented_action", "pin": 17} ``` 4. If the remote dispatcher exposes additional actions or inadequately validates action names, it may execute functionality outside the intended GPIO on/off interface. Exploitation beyond request submission is conditional on the behavior of the external server. ### Impact Assessment The confirmed impact is the ability to submit arbitrary action identifiers to the remote RPC endpoint. If the server has undocumented or privileged handlers, this could allow operations beyond GPIO switching with the privileges of the Pi RPC service. The precise server- ...[truncated 82 chars]
Remediation
View remediation
&2 exit 2 ;; esac ``` Additionally: - Maintain an explicit server-side allowlist independent of client validation. - Map accepted public action names to fixed internal handlers rather than dynamically evaluating or dispatching arbitrary strings. - Run the RPC service with only the GPIO permissions required for its intended function. - Return an error for every unknown action and log rejected requests without recording sensitive authentication material. - Add tests confirming that malformed, empty, and undocumented action names are rejected. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.sh:6
Finding

Unsafe JSON Construction from Unvalidated Arguments

Content
View full analysis
| gpio_off " # exit 1 代表程式異常終止(回傳非 0 值) exit 1 fi ``` ```bash curl -s http://$PI_IP:9000/run \ -H "Content-Type: application/json" \ -d "{\"action\": \"$ACTION\", \"pin\": $PIN}" ``` ### Technical Analysis The script constructs JSON through shell string interpolation rather than using a JSON serializer. `PIN` is inserted as an unquoted raw JSON expression, and special characters in `ACTION` are not escaped. Although shell command substitution inside an already-expanded argument is not re-evaluated as shell syntax, an attacker can manipulate the structure or validity of the JSON request. For example, a crafted pin can append additional properties: ```bash ./scripts/main.sh gpio_on '17, "additional": true' ``` This produces: ```json {"action": "gpio_on", "pin": 17, "additional": true} ``` A crafted action containing quotation marks can similarly terminate the intended JSON string or create malformed JSON. Whether injected properties have additional effects depends on the external RPC server's parser and request schema. ### Attack Path 1. An attacker gains the ability to control arguments passed to `main.sh`. 2. The attacker supplies a nonempty but structurally malicious value, such as: ```bash ./scripts/main.sh gpio_on '17, "force": true' ``` 3. The nonempty check accepts the value. 4. The script interpolates it directly into the request body. 5. The remote endpoint receives attacker-defined JSON structure rather than the intended two-field object. 6. If the endpoint recognizes an injected property or performs unsafe type coercion, the attacker m ...[truncated 477 chars]
Remediation
View remediation
&2; exit 2 ;; esac if [[ ! "$PIN" =~ ^[0-9]+$ ]]; then echo "Pin must be an integer" >&2 exit 2 fi ``` Apply a hardware-appropriate pin range and, preferably, an explicit list of pins that the skill is authorized to control. Use a JSON serializer instead of interpolation: ```bash payload="$(jq -n \ --arg action "$ACTION" \ --argjson pin "$PIN" \ '{action: $action, pin: $pin}')" curl --fail-with-body --silent --show-error \ -H "Content-Type: application/json" \ --data-binary "$payload" \ "https://pi.example.local:9000/run" ``` The server must also enforce a strict schema: - Reject unknown properties. - Require `action` to be an allowed string. - Require `pin` to be an integer in the permitted range. - Reject duplicate JSON keys and unexpected value types. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.sh:22
Finding

Unauthenticated Plaintext Hardware-Control Channel

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/main.sh (reported line 23)May include surrounding context.

sh
# 請確保執行此腳本的電腦與樹莓派在同一個區域網路 (LAN) 下
PI_IP="192.168.0.14"
# ---------- 發送請求 ----------
# 使用 curl 工具發送 HTTP POST 請求
# -s (silent): 靜音模式,不顯示進度條或錯誤訊息
# http://$PI_IP:9000/run: 目標 API 地址
curl -s http://$PI_IP:9000/run \

Static analysis

No suspicious patterns detected.