Audit History
picocom - 5 audits
Audit version 5
Latest Medium RiskJan 16, 2026, 08:12 PM
Legitimate IoT security testing tool. The static analysis flagged 664 patterns but these are FALSE POSITIVES - documentation of standard pentesting commands to run on TARGET DEVICES, not malicious host behavior. The only actual code (serial_helper.py) has one controlled subprocess feature for trigger scripts with 30-second timeout. Authorization requirements are documented. Safe for marketplace.
Medium Risk Issues (1)
Low Risk Issues (1)
Risk Factors
⚙️ External commands (3)
📁 Filesystem access (2)
🌐 Network access (2)
Audit version 4
Medium RiskJan 16, 2026, 08:12 PM
Legitimate IoT security testing tool. The static analysis flagged 664 patterns but these are FALSE POSITIVES - documentation of standard pentesting commands to run on TARGET DEVICES, not malicious host behavior. The only actual code (serial_helper.py) has one controlled subprocess feature for trigger scripts with 30-second timeout. Authorization requirements are documented. Safe for marketplace.
Medium Risk Issues (1)
Low Risk Issues (1)
Risk Factors
⚙️ External commands (3)
📁 Filesystem access (2)
🌐 Network access (2)
Audit version 3
Medium RiskJan 10, 2026, 11:40 AM
Legitimate IoT security testing tool with documented external command execution capability for trigger scripts in monitor mode. The subprocess execution is user-controlled, timeout-limited, and intended for legitimate security testing workflows. No network calls or credential theft patterns detected.
Medium Risk Issues (1)
Low Risk Issues (1)
Risk Factors
⚙️ External commands (1)
📁 Filesystem access (2)
Audit version 2
Medium RiskJan 10, 2026, 11:40 AM
Legitimate IoT security testing tool with documented external command execution capability for trigger scripts in monitor mode. The subprocess execution is user-controlled, timeout-limited, and intended for legitimate security testing workflows. No network calls or credential theft patterns detected.
Medium Risk Issues (1)
Low Risk Issues (1)
Risk Factors
⚙️ External commands (1)
📁 Filesystem access (2)
Audit version 1
Medium RiskJan 10, 2026, 11:40 AM
Legitimate IoT security testing tool with documented external command execution capability for trigger scripts in monitor mode. The subprocess execution is user-controlled, timeout-limited, and intended for legitimate security testing workflows. No network calls or credential theft patterns detected.