Back to skill

Security audit

RDK X5 App Resources

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed RDK X5 hardware-demo guide; it can affect attached devices, but that matches its purpose and it contains no bundled executable code.

Install only if you are working on an RDK X5 board. Before running GPIO, bus, camera, media pipeline, or ISP commands, confirm the board model, pin numbering, voltage and current limits, connected peripherals, and whether the command may move, power, display, capture, or retune hardware.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill gives concrete instructions for GPIO control, motor/relay use, camera access, video pipelines, and ISP tuning without pairing them with explicit safety warnings about physical effects, device state changes, or environment-specific risks. In an agent context, this increases the chance that automation triggers hardware actions, tuning changes, or sensor/video operations without adequate user confirmation or operational safeguards.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.