Install
$ agentstack add skill-wang200935-security-agent-skills-smart-card-driver-debug ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Smart Card Reader Driver Debugging (Windows)
Core Concept: Synchronous vs Asynchronous Cards
| Card Type | Examples | Protocol | PC/SC Support | |-----------|----------|----------|---------------| | Asynchronous (ISO 7816) | SIM, bank cards, eID, Java Card | T=0 / T=1 | Yes (Native) | | Synchronous (Memory) | SLE4442, SLE4428, AT88SC, AT24Cxx | I2C / 2-wire / 3-wire | Not supported by standard PC/SC |
Key insight: Microsoft CCID driver (wudfusbcciddriver.inf) only implements ISO 7816 T=0/T=1. It returns empty GET_FEATURE_REQUEST (no SET_CARD_TYPE), and SCardConnect with T=0/T=1 fails with 0x00000005 (SCARDEPROTO_MISMATCH).
The Working Path: Vendor CT-API
Alcor Micro readers (AU9540, AK9543, AU9520) ship with CTAlc001.dll — a proprietary CT-API (ISO 7816-4 CT-BCS) that bypasses PC/SC entirely.
DLL Exports (CTAlc001.dll)
CT_init(ctn: uint16, pn: uint16) -> int16
CT_data(ctn, dad, sad, lenc, command, lenr, response) -> int16
CT_close(ctn) -> int16
Python 32-bit Interop (Required — DLL is 32-bit)
# Download 32-bit Python embed package
Invoke-WebRequest -Uri "https://www.python.org/ftp/python/3.11.9/python-3.11.9-embed-win32.zip" -OutFile "python32.zip"
Expand-Archive python32.zip -DestinationPath C:\Temp\py32
import ctypes
dll = ctypes.windll.LoadLibrary(r"C:\path\to\CTAlc001.dll")
dll.CT_init.argtypes = [ctypes.c_uint16, ctypes.c_uint16]
dll.CT_init.restype = ctypes.c_int16
dll.CT_data.argtypes = [
ctypes.c_uint16,
ctypes.POINTER(ctypes.c_ubyte), # dad
ctypes.POINTER(ctypes.c_ubyte), # sad
ctypes.c_uint16, # lenc
ctypes.POINTER(ctypes.c_ubyte), # command
ctypes.POINTER(ctypes.c_uint16), # lenr
ctypes.POINTER(ctypes.c_ubyte), # response
]
dll.CT_data.restype = ctypes.c_int16
dll.CT_close.argtypes = [ctypes.c_uint16]
dll.CT_close.restype = ctypes.c_int16
# Initialize (port 100 = USB for Alcor)
handle = dll.CT_init(0, 100) # returns 0 on success
SLE4442 Commands via CT-API
# Verify PSC (default FFFFFF)
cmd = bytes([0xFF, 0x20, 0x00, 0x00, 0x03, 0xFF, 0xFF, 0xFF])
# Read 4 bytes at offset 0
cmd = bytes([0xFF, 0xB0, 0x00, 0x00, 0x04])
# Read error counter (address 0x1F)
cmd = bytes([0xFF, 0xB0, 0x00, 0x1F, 0x01])
# Write byte
cmd = bytes([0xFF, 0xD0, 0x00, offset, 0x01, value])
# Change PSC (after verify)
cmd = bytes([0xFF, 0xD2, 0x00, 0x00, 0x03, new_p1, new_p2, new_p3])
Driver Binding Strategies (Critical Blocker)
Problem
Windows binds Alcor readers (VID058F) to Microsoft CCID. Rebranded readers (e.g., Pincop ICU02 = VID2CE3 PID_9563) have no matching INF.
Strategy 1: Modify Original INF + Test Signing (Most Reliable)
- Copy original driver folder (contains
.sys,.dll,.inf,.cat) - Edit
SZCCID.INF→ add your VID/PID to[DeviceList.NTamd64] - Enable test signing:
bcdedit /set testsigning on(reboot) - Re-sign
.catwith self-cert or usepnputil /add-driverwith modified INF - Force bind:
pnputil /remove-device→pnputil /scan-devices
Strategy 2: Registry Force-Bind (No Reboot, Fragile)
# Find device instance
$inst = "USB\VID_2CE3&PID_9563\5&3639e268&0&4"
# Set driver to SZCCID (oem58.inf = AlcorMicro)
pnputil /remove-device $inst
# Edit registry:
# HKLM\SYSTEM\CurrentControlSet\Enum\USB\VID_2CE3&PID_9563\...\Driver = "{50dd5230-ba8a-11d1-bf5d-0000f805f530}\0001"
# HKLM\...\Service = "szccid"
pnputil /scan-devices
Strategy 3: DevCon (If Available)
devcon update "SZCCID.INF" "USB\VID_2CE3&PID_9563"
Alcor Driver Package Structure
AU9540_V1.7.2.0\program_files\AlcorMicro\x64\
├── CTAlc001.dll ← CT-API (32-bit & 64-bit versions exist)
├── SZCCID.sys ← Kernel driver (binds to device)
├── SzCcidV1900.dll ← Co-installer / user-mode CCID
├── SCPwrSetSvr.exe ← Power management
├── SZCCID.INF ← Installation INF
├── szccid.cat ← WHQL signature (must re-sign if INF modified)
└── AlcGener.sys ← Generic helper
Common Error Codes
| Code | Meaning | Context | |------|---------|---------| | 0x00000005 | SCARDEPROTOMISMATCH | T=0/T=1 connect on synchronous card | | 0x00000006 | SCARDENOSMARTCARD | MS CCID can't detect synchronous card (no ATR) | | 0xFFF8 (-8) | ERRCT (CT-API) | CT_init failed — device not bound to SZCCID.sys | | 0x00313520 | IOCTLSMARTCARDGETFEATURE_REQUEST | Microsoft CCID returns empty list (no features) | | 31 (0x1F) | Service STOPPED | sc query szccid — driver loaded but not bound | | WinError 193 | Wrong bitness | Loading 32-bit DLL in 64-bit Python (or vice versa) |
Critical Blockers (Lessons from Pincop ICU02 = VID2CE3 PID9563)
Secure Boot Blocks Test Signing
bcdedit /set testsigning on
→ "The value is protected by Secure Boot policy and cannot be modified or deleted."
If Secure Boot is enabled, you CANNOT enable test signing. Options:
- Enter UEFI/BIOS → disable Secure Boot → reboot → enable test signing → reboot → install driver
- Buy a reader whose VID/PID is in the vendor's WHQL-signed INF (e.g., ACS ACR38U)
- Buy the same chip with original VID (Alcor AU9540 = VID058F PID9540)
Registry Force-Bind Doesn't Survive pnputil /enable-device
Setting Service=SzCCID in the Enum key works temporarily, but pnputil /enable-device triggers PnP re-enumeration which overrides Service back to WUDFRd based on USB\Class_0B CompatibleID. The registry value remains SzCCID but the actual driver stack reverts to WUDF CCID.
Workaround attempted: Disable device → change registry → enable device. Result: PnP still re-binds to wudfusbcciddriver.inf because it's the highest-ranked signed driver for USB\Class_0B&SubClass_00&Prot_00.
MS CCID Direct IOCTL Access (Dead End)
Opening \\?\USB#VID_2CE3&PID_9563#...#{a5dcbf10-...} via CreateFileW succeeds, but DeviceIoControl only responds to 2 IOCTLs:
IOCTL+0x028→ returns empty (ack-only)IOCTL+0x038→ returns02000000(version/capabilities DWORD)
ALL standard smartcard IOCTLs return ERROR_INVALID_FUNCTION (err=1):
- GETFEATUREREQUEST, SETCARDTYPE, POWER, TRANSMIT, SETPROTOCOL, ISPRESENT → all fail
- CCID_ESCAPE (0x004) with raw CCID messages → fails
- WriteFile/ReadFile → written=0 (WUDF doesn't support raw I/O)
Conclusion: WUDF CCID driver is a sealed box. Cannot send CCID escape commands or SETCARDTYPE. The only path out is replacing the driver entirely.
CTAlc001.dll Bitness
CTAlc001.dllfrom Alcor x64 package is PE32 (i386, 32-bit)SZCCID.sysis AMD64 (64-bit)- Must use 32-bit Python to load the DLL:
python-3.11.9-embed-win32.zip - 64-bit Python →
WinError 193: not a valid Win32 application - DLL communicates with kernel driver via DeviceIoControl (works across 32→64 bitness)
- BUT: CT_init still returns -8 if the kernel driver isn't bound to the device
32-bit Python Setup (Embed Package)
# Download 32-bit embeddable Python (no installer needed)
Invoke-WebRequest -Uri "https://www.python.org/ftp/python/3.11.9/python-3.11.9-embed-win32.zip" -OutFile "C:\Temp\py311-32.zip"
Expand-Archive -Path C:\Temp\py311-32.zip -DestinationPath C:\Python311-32 -Force
# Verify it's 32-bit
C:\Python311-32\python.exe -c "import struct; print(struct.calcsize('P')*8)"
# → 32
⚠️ SLE4442 Safety Rules (MANDATORY)
PSC has a 3-strike lockout — PERMANENT if exhausted.
- Always read Security Memory first → check Error Counter (EC) byte
- Never blind-guess PSC — common defaults:
FF FF FF,B2 B2 B2 - Stop when EC ≤ 1 attempt remaining — preserve at least 1 try
- Successful Verify resets EC — no attempt consumed when PSC is correct
Full attack surface analysis: see smart-card-reader-sle4442 → references/sle4442-security-attacks.md
Debugging Checklist
- Verify hardware:
pnputil /enum-devices→ confirm VID/PID - Check current driver: Look for
wudfusbcciddriver.inf(Microsoft) vsszccid.inf(Alcor) - Install Alcor driver:
pnputil /add-driver SZCCID.INF /install - Force re-enumeration: Remove device → scan
- Test CT-API: 32-bit Python +
CT_init(0, 100)→ must return 0 - If CT_init returns -8: Device still bound to Microsoft CCID → fix binding
Reader Replacement Recommendations
When driver binding cannot be resolved (Secure Boot enabled, unsigned INF rejected, PnP overrides registry), replacing the reader is the most practical solution.
Recommended Readers for SLE4442 (Taiwan availability)
| Reader | VID:PID | Price (NT$) | Why | |--------|---------|-------------|-----| | ACS ACR38U | 072B:021C | 300–800 | WHQL-signed driver, full SLE4442/4428 SDK, most Python examples, globally most popular | | ACS ACR39U | 072B:021D | 400–1000 | ACR38U upgraded version | | Alcor AU9540 (original VID) | 058F:9540 | 150–350 | Same chip as Pincop ICU02 but with Alcor's original VID — existing SZCCID driver binds automatically |
Shopee (蝦皮) Search Keywords
ACR38U, SLE4442 讀卡機, 冷氣卡 讀卡機, AU9540 讀卡機, IC卡讀卡器 4442
Before Buying — Verify
- ✅ Description mentions SLE4442 / 4428 / 同步卡 / 記憶卡
- ❌ Only mentions CPU卡 / ISO 7816 → cannot read synchronous cards
- ❌ Rebranded readers with non-standard VIDs (unless vendor provides signed driver)
References
references/alcor-au9540-driver-notes.md— Detailed Alcor AU9540/AK9543 driver internalsreferences/sle4442-ctapi-commands.md— Complete SLE4442 command set for CT-APIreferences/windows-driver-binding-tactics.md— Registry/INF/test-signing tacticsreferences/sle4442-security-attacks.md— Complete SLE4442 attack surface analysis
Scripts
scripts/test_ctapi_sle4442.py— Ready-to-run CT-API test (requires 32-bit Python)scripts/force_bind_szccid.ps1— PowerShell script to force device bind to SZCCID
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Wang200935
- Source: Wang200935/security-agent-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.