ruview-mmwave
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions to execute local scripts for hardware provisioning and data bridging, specifically
firmware/esp32-csi-node/provision.py,scripts/mmwave_fusion_bridge.py, andscripts/passive-radar.js. - [CREDENTIALS_UNSAFE]: The documentation for the provisioning script includes examples where Wi-Fi credentials (SSID and password) are passed as command-line arguments. Although placeholders like "secret" are used, this pattern can lead to credential exposure in shell history or process logs if used with real sensitive information.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external radar sensors and WiFi-CSI nodes. While the data is technical (vitals, distance, presence), the ingestion of untrusted external sensor data alongside tool access (Bash, Write, Edit) creates a theoretical attack surface, though the risk is currently low given the domain-specific nature of the data.
Audit Metadata