agentsclimarketplace

Security updates

Skill beriberikix/zephyr-agent-skills/skills/security-updates

A complete catalog of Agent Skills (agentskills.io) for Zephyr RTOS development.

Install
npx -y skills add beriberikix/zephyr-agent-skills --skill security-updates

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Secure boot and firmware update workflows for Zephyr RTOS. Covers MCUboot integration, production image signing, DFU protocols (MCUmgr), fail-safe rollback mechanisms, and mbedTLS crypto basics. Trigger when implementing over-the-air (OTA) updates, securing the boot process, or managing cryptographic keys.

SKILL.md

3.4 KB, as published. Nobody here has run it

Zephyr Security & Updates

Build production-ready, secure embedded systems using Zephyr's modular security stack and MCUboot bootloader.

Core Workflows

1. MCUboot Integration

Set up the secure bootloader and define fail-safe flash partitions.

2. Image Signing

Ensure firmware integrity with production-grade digital signatures.

3. DFU Protocols

Transport updates securely using MCUmgr or cloud-based OTA.

4. Rollback Protection

Implement atomic swaps and image confirmation to prevent bricking devices.

5. Crypto Basics

Implement secure storage and cryptographic operations using mbedTLS.

Quick Start (Kconfig for Secure Boot)

# Enable MCUboot support in application
CONFIG_BOOTLOADER_MCUBOOT=y
# Build with MCUboot using Sysbuild
west build -b nucleo_f401re --sysbuild samples/basic/blinky

Professional Patterns (Security-First)

  • Production Keys: Never use default MCUboot keys. Provision unique keys during manufacturing.
  • Heartbeat Confirmation: Only confirm a new image after the application has successfully connected to its cloud backend.
  • Version Integrity: Enable version monotonicity to prevent accidental or malicious firmware downgrades.

Automation Tools

Examples & Templates

Validation Checklist

  • Signed image verifies at boot and unsigned/tampered image is rejected.
  • DFU flow completes end-to-end and boots into the new slot.
  • Rollback behavior triggers correctly when image confirmation is withheld.
  • Key handling and version policy prevent downgrade and test-key usage in production configs.

Resources

  • References:
    • mcuboot_integration.md: Partition layouts and setup.
    • image_signing.md: Key management and imgtool usage.
    • dfu_protocols.md: MCUmgr commands and cloud OTA.
    • rollback_protection.md: Swap mechanisms and confirmation code.
    • crypto_basics.md: mbedTLS and secure storage.
  • Scripts:
    • mcuboot_version_guard.py: Version monotonicity checker for release gates.
  • Assets:
    • mcuboot_prj_fragment.conf: Secure-update config baseline.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.