# Pt Embedded Device Assessment

> Performs authorized security assessment of embedded and IoT devices across hardware, firmware, interfaces, and update mechanisms. Use when testing device boot flows, debug interfaces, firmware integrity, and local/network attack surfaces.

- **Type:** Skill
- **Install:** `agentstack add skill-santosomar-ethical-hacking-agent-skills-pt-embedded-device-assessment`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [santosomar](https://agentstack.voostack.com/s/santosomar)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [santosomar](https://github.com/santosomar)
- **Source:** https://github.com/santosomar/ethical-hacking-agent-skills/tree/main/skills/pt-embedded-device-assessment

## Install

```sh
agentstack add skill-santosomar-ethical-hacking-agent-skills-pt-embedded-device-assessment
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Embedded Device Assessment

## Authorized Use Only

Embedded testing can damage hardware or interrupt operations. Confirm explicit authorization, safe handling procedures, and recovery plans before interacting with devices.

## Objectives

1. Evaluate device security from physical access through runtime operation.
2. Identify weaknesses in firmware, interfaces, and update paths.
3. Determine practical exploitability and fleet-level impact.

## Workflow

1. Define test environment:
   - Device models, firmware versions, accessories, and network topology
   - Recovery procedures, spare hardware, and fail-safe boundaries
2. Enumerate interfaces:
   - Physical (UART/JTAG/SWD), wireless, network services, companion apps
   - Boot modes and exposed maintenance/debug channels
3. Assess firmware and boot trust:
   - Firmware extraction and integrity validation where authorized
   - Secure boot, signature checks, rollback protections, key handling
4. Evaluate runtime security:
   - Local and remote service hardening
   - Credential storage, update mechanism security, telemetry exposure
5. Validate impact and remediation:
   - Demonstrate constrained exploitability
   - Recommend secure defaults and manufacturing/update controls

## Output Template

```markdown
# Embedded Assessment Output

## Device Context
- Model/version:
- Firmware build:
- Deployment context:

## Interface Findings
- Interface:
  - Exposure:
  - Weakness:
  - Evidence:
  - Impact:

## Firmware and Boot Findings
- Control tested:
  - Result:
  - Evidence:
  - Risk:

## Remediation Plan
- Immediate mitigations:
- Long-term architecture fixes:
- Validation/retest steps:
```

## Quality Checks

- Safety and recovery constraints are documented and followed.
- Findings distinguish single-device vs fleet-wide risk.
- Recommendations address lifecycle: manufacturing, provisioning, updates, and decommissioning.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [santosomar](https://github.com/santosomar)
- **Source:** [santosomar/ethical-hacking-agent-skills](https://github.com/santosomar/ethical-hacking-agent-skills)
- **License:** Apache-2.0

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-santosomar-ethical-hacking-agent-skills-pt-embedded-device-assessment
- Seller: https://agentstack.voostack.com/s/santosomar
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
