技能 iotnet 審計紀錄
📦

審計紀錄

iotnet - 6 審計

審計版本 6

最新 中風險

Jun 28, 2026, 06:07 PM

Static analysis found many shell command examples and sudo-based live capture instructions. Review confirms these are documentation for an IoT network security tool, not hidden malware, but they can run external commands with user-provided paths, filters, and elevated privileges. Weak cryptography and hardcoded IP indicators appear to be false positives or examples; no prompt injection or exfiltration intent was found.

1
已掃描檔案
143
分析行數
6
發現
codex
審計單位
中風險問題 (2)
Privileged Live Packet Capture
The skill instructs users to run live traffic capture with sudo. This is legitimate for packet capture, but it grants elevated privileges and may expose sensitive network data if used outside an authorized environment.
External Command Execution With User Inputs
The skill directs the assistant to execute iotnet commands using file paths, interfaces, IP filters, capture filters, display filters, and config paths supplied during the workflow. This can be safe when arguments are validated and quoted, but it creates command execution and injection risk if used carelessly.
低風險問題 (2)
Hardcoded Private IP Example
The hardcoded IP finding is a documentation example for filtering traffic by one private network address. It does not identify an external destination or data exfiltration endpoint.
Weak Cryptography Scanner False Positive
Static analysis flagged weak cryptography on metadata and heading lines, but those lines contain the skill name and network analysis description. No cryptographic algorithm use was found in the reviewed file.

偵測到的模式

Sudo Command PatternNetwork Reconnaissance Capability

審計版本 5

低風險

Jan 16, 2026, 08:00 PM

This is a pure documentation skill providing AI guidance for using the iotnet network analysis tool. Static findings are false positives: the scanner misinterpreted markdown code formatting as shell execution, documented sudo requirements for legitimate packet capture as privilege escalation, and references to detecting weak cryptography as actual weak algorithms. The skill explicitly requires authorization and is designed for defensive security assessment.

2
已掃描檔案
324
分析行數
1
發現
claude
審計單位
未發現安全問題

審計版本 4

低風險

Jan 16, 2026, 08:00 PM

This is a pure documentation skill providing AI guidance for using the iotnet network analysis tool. Static findings are false positives: the scanner misinterpreted markdown code formatting as shell execution, documented sudo requirements for legitimate packet capture as privilege escalation, and references to detecting weak cryptography as actual weak algorithms. The skill explicitly requires authorization and is designed for defensive security assessment.

2
已掃描檔案
324
分析行數
1
發現
claude
審計單位
未發現安全問題

審計版本 3

安全

Jan 10, 2026, 11:33 AM

This is a pure prompt-based skill containing only a SKILL.md instruction file. The skill provides guidance to AI assistants on how to help users analyze IoT network traffic using the external iotnet tool. No executable code, scripts, network calls, or file system access are performed by the skill itself.

1
已掃描檔案
143
分析行數
0
發現
claude
審計單位
未發現安全問題

審計版本 2

安全

Jan 10, 2026, 11:33 AM

This is a pure prompt-based skill containing only a SKILL.md instruction file. The skill provides guidance to AI assistants on how to help users analyze IoT network traffic using the external iotnet tool. No executable code, scripts, network calls, or file system access are performed by the skill itself.

1
已掃描檔案
143
分析行數
0
發現
claude
審計單位
未發現安全問題

審計版本 1

安全

Jan 10, 2026, 11:33 AM

This is a pure prompt-based skill containing only a SKILL.md instruction file. The skill provides guidance to AI assistants on how to help users analyze IoT network traffic using the external iotnet tool. No executable code, scripts, network calls, or file system access are performed by the skill itself.

1
已掃描檔案
143
分析行數
0
發現
claude
審計單位
未發現安全問題