AgentStack
SKILL verified Apache-2.0 Self-run

Pt Embedded Device Assessment

skill-santosomar-ethical-hacking-agent-skills-pt-embedded-device-assessment · by santosomar

Performs authorized security assessment of embedded and IoT devices across hardware, firmware, interfaces, and update mechanisms. Use when testing device boot flows, debug interfaces, firmware integrity, and local/network attack surfaces.

No reviews yet
0 installs
14 views
0.0% view→install

Install

$ agentstack add skill-santosomar-ethical-hacking-agent-skills-pt-embedded-device-assessment

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Pt Embedded Device Assessment? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Embedded Device Assessment

Authorized Use Only

Embedded testing can damage hardware or interrupt operations. Confirm explicit authorization, safe handling procedures, and recovery plans before interacting with devices.

Objectives

  1. Evaluate device security from physical access through runtime operation.
  2. Identify weaknesses in firmware, interfaces, and update paths.
  3. Determine practical exploitability and fleet-level impact.

Workflow

  1. Define test environment:
  • Device models, firmware versions, accessories, and network topology
  • Recovery procedures, spare hardware, and fail-safe boundaries
  1. Enumerate interfaces:
  • Physical (UART/JTAG/SWD), wireless, network services, companion apps
  • Boot modes and exposed maintenance/debug channels
  1. Assess firmware and boot trust:
  • Firmware extraction and integrity validation where authorized
  • Secure boot, signature checks, rollback protections, key handling
  1. Evaluate runtime security:
  • Local and remote service hardening
  • Credential storage, update mechanism security, telemetry exposure
  1. Validate impact and remediation:
  • Demonstrate constrained exploitability
  • Recommend secure defaults and manufacturing/update controls

Output Template

# Embedded Assessment Output

## Device Context
- Model/version:
- Firmware build:
- Deployment context:

## Interface Findings
- Interface:
  - Exposure:
  - Weakness:
  - Evidence:
  - Impact:

## Firmware and Boot Findings
- Control tested:
  - Result:
  - Evidence:
  - Risk:

## Remediation Plan
- Immediate mitigations:
- Long-term architecture fixes:
- Validation/retest steps:

Quality Checks

  • Safety and recovery constraints are documented and followed.
  • Findings distinguish single-device vs fleet-wide risk.
  • Recommendations address lifecycle: manufacturing, provisioning, updates, and decommissioning.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.