picocom
Audit IoT UART Consoles with picocom
UART testing can be slow when serial output is noisy and difficult to capture. This skill guides authorized serial sessions with logging, prompt detection, and structured embedded device checks.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "picocom" from https://skillstore.io/skills/brownfinesecurity-picocom.md and its manifest at https://skillstore.io/api/skills/brownfinesecurity-picocom/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "picocom". Monitor a device boot over UART for one minute.
Expected outcome:
A short boot timeline lists the detected baud rate, kernel messages, service starts, login prompts, and any repeated errors.
Using "picocom". Run a small command checklist on an authorized BusyBox shell.
Expected outcome:
A concise report summarizes device identity, network state, writable paths, notable services, and exact log references.
Using "picocom". Send AT commands to a modem console.
Expected outcome:
A readable response summary separates successful replies, modem errors, identifiers, and commands that need a longer timeout.
Security Audit
CriticalStatic findings were a mix of normal serial-device tooling and high-risk dual-use exploitation guidance. I confirmed the critical workflows around password file access, SSH persistence, backdoor accounts, bootloader root-shell bypass, credential searches, firmware extraction, network reconnaissance, and shell=True trigger execution; I dismissed documentation links, Markdown backticks, normal /dev/ttyUSB use, and log cleanup as false positives. Static review was capped at 400/457 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
Confirmed security concerns (67)
Show all 67 confirmed findings
Capability review items (113)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (50)
๐ Network access (18)
๐ Filesystem access (50)
๐ Env variables (1)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/brownfinesecurity-picocom/audits/10?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/brownfinesecurity-picocom?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/brownfinesecurity-picocom?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/brownfinesecurity-picocom/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/brownfinesecurity-picocom.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
BrownFineSecurity. (2026). picocom security audit report (audit version 10) [Author version unspecified]. Skillstore. https://skillstore.io/skills/brownfinesecurity-picocom/audits/10BibTeX citation
@techreport{brownfinesecurity-brownfinesecurity-picocom-2026,
author = {BrownFineSecurity},
title = {picocom security audit report (audit version 10)},
institution = {Skillstore},
year = {2026},
number = {10},
url = {https://skillstore.io/skills/brownfinesecurity-picocom/audits/10},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "picocom security audit report (audit version 10)"
version: "unspecified"
type: report
authors:
- name: "BrownFineSecurity"
date-released: "2026-07-09"
url: "https://skillstore.io/skills/brownfinesecurity-picocom/audits/10"
identifiers:
- type: other
value: "skillstore:brownfinesecurity-picocom:audit:10"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Capture Boot Logs
Record boot output from an embedded device and identify prompts, baud issues, and startup services.
Inspect Authorized Consoles
Run controlled commands on a lab device and preserve a session transcript for a security report.
Test Modem AT Interfaces
Send AT commands to cellular or satellite modems and classify normal, error, and connection responses.
Try These Prompts
Use the picocom skill to connect to my authorized device on /dev/ttyUSB0 at 115200 baud. Capture the first prompt and summarize what you see.
Monitor the UART output for 60 seconds while I reboot the device. Save a session log and summarize boot stages, prompts, and errors.
Use the serial helper with the prompt I provide. Run a small authorized checklist and return a concise findings summary with evidence from the log.
Capture a baseline, run my approved trigger command, and compare UART output before, during, and after the trigger. Highlight new warnings or crashes.
Best Practices
- Use this skill only on devices you own or have written authorization to test.
- Store session logs outside shared temporary paths when they may contain secrets.
- Start with passive monitoring before running commands that change device state.
Avoid
- Do not use persistence, backdoor, or shell escape examples on systems without explicit authorization.
- Do not publish raw session logs because they may include passwords, keys, or device identifiers.
- Do not assume one baud rate, prompt pattern, or line ending works for every embedded device.
Frequently Asked Questions
What does this skill help me do?
Does it require hardware access?
Can it use Claude, Codex, and Claude Code?
Can it monitor without sending commands?
Why are logs a security concern?
Is this safe for any device?
Developer Details
Author
BrownFineSecurityLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
3e4b6c31a74a3bd1a291c98cf585d720cb9fbc88
Maintenance freshness
7/18/2026
Usage
5 downloads ยท 201 views
File structure