ruview-hardware-setup
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill uses
python -cto execute multi-line Python logic directly from the command line. This is used to programmatically manipulate environment variables (strippingMSYSTEMvariables and settingPATH) and launch the ESP-IDF build system usingsubprocess.run. This implementation is a workaround for compatibility issues between Windows shell environments and the ESP-IDF toolchain. - [INDIRECT_PROMPT_INJECTION]: The serial monitoring functionality introduces a surface for ingesting untrusted data from external hardware.
- Ingestion points: Serial data is read from the physical device on
COM8usingser.readline()inSKILL.md. - Boundary markers: None; the raw serial stream is processed directly.
- Capability inventory: The skill utilizes
Bash,python -m esptool, andcargo runfor device interaction and server hosting. - Sanitization: The output is decoded with
errors='replace'and printed to the terminal, but there is no validation of the content received from the hardware.
Audit Metadata