skills/ruvnet/ruview/ruview-mmwave/Gen Agent Trust Hub

ruview-mmwave

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions to execute local scripts for hardware provisioning and data bridging, specifically firmware/esp32-csi-node/provision.py, scripts/mmwave_fusion_bridge.py, and scripts/passive-radar.js.
  • [CREDENTIALS_UNSAFE]: The documentation for the provisioning script includes examples where Wi-Fi credentials (SSID and password) are passed as command-line arguments. Although placeholders like "secret" are used, this pattern can lead to credential exposure in shell history or process logs if used with real sensitive information.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external radar sensors and WiFi-CSI nodes. While the data is technical (vitals, distance, presence), the ingestion of untrusted external sensor data alongside tool access (Bash, Write, Edit) creates a theoretical attack surface, though the risk is currently low given the domain-specific nature of the data.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 08:03 AM
Security Audit — agent-trust-hub — ruview-mmwave