ruview-hardware-setup

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses python -c to execute multi-line Python logic directly from the command line. This is used to programmatically manipulate environment variables (stripping MSYSTEM variables and setting PATH) and launch the ESP-IDF build system using subprocess.run. This implementation is a workaround for compatibility issues between Windows shell environments and the ESP-IDF toolchain.
  • [INDIRECT_PROMPT_INJECTION]: The serial monitoring functionality introduces a surface for ingesting untrusted data from external hardware.
  • Ingestion points: Serial data is read from the physical device on COM8 using ser.readline() in SKILL.md.
  • Boundary markers: None; the raw serial stream is processed directly.
  • Capability inventory: The skill utilizes Bash, python -m esptool, and cargo run for device interaction and server hosting.
  • Sanitization: The output is decoded with errors='replace' and printed to the terminal, but there is no validation of the content received from the hardware.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 08:03 AM
Security Audit — agent-trust-hub — ruview-hardware-setup