Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Periph Compliance Accessibility And Security

ASecurity

Use before shipping a peripheral or assessing one: compliance and certification including USB-IF, CE, FCC and the logo programmes, accessibility and the design decisions that include or exclude users, and peripheral security — malicious devices, BadUSB-class attacks, DMA exposure and firmware update integrity.

2 stars
0 votes
0 copies
2 views
Added 9/19/2026
ai-agentsrustgotestingdebuggingdatabasesecurity

Security Analysis

A100/100

Scanned 9/19/2026

$npx -y skills add the-vibey-project/vibey --skill periph-compliance-accessibility-and-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Periph Compliance Accessibility And Security?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Periph Compliance Accessibility And Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/the-vibey-project-periph-compliance-accessibility-and-security/badge)](https://www.skillsdirectory.com/skills/the-vibey-project-periph-compliance-accessibility-and-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: periph-compliance-accessibility-and-security
description: "Use before shipping a peripheral or assessing one: compliance and certification including USB-IF, CE, FCC and the logo programmes, accessibility and the design decisions that include or exclude users, and peripheral security — malicious devices, BadUSB-class attacks, DMA exposure and firmware update integrity."
---

# Computer Peripherals: Compliance and Certification, Accessibility, and Peripheral Security

> **Part 5 of 6** of the *Computer Peripherals: Design, Building, Standards and Programming* reference (plugin `computer-peripherals-design-and-standards`), covering §22–§24. Sibling skills: `periph-stack-usb-thunderbolt-and-wireless` (§0–§5), `periph-buses-pcie-hid-keyboards-mice-and-displays` (§6–§11), `periph-audio-printers-storage-controllers-and-haptics` (§12–§15), `periph-designing-firmware-pcb-and-debugging` (§16–§21), `periph-reference` (§25–§30). Section numbers are shared across the set; a reference written as §N → `skill` points into that sibling skill.
>
> **Currency:** The protocols are stable and long-lived. Two areas are moving. See §25 → `periph-reference` for USB bandwidth and labelling, and display interface bandwidth tiers.

> **⚠️ The layer where a computer meets the physical world — and the one where standards
> politics, signal integrity, human factors and firmware all collide at once.**
>
> **Complements a computer-hardware reference (the host side), an electromagnetism
> reference (signal integrity, differential pairs, EMC), and a semiconductor reference
> (the microcontrollers involved).**
>
> **⚠️ GOTCHA** boxes mark where the marketing name and the actual capability diverge —
> and this domain has the worst naming in computing.
>
> **The three ideas that organize this document:**
> 1. **⚠️ THE CONNECTOR IS NOT THE PROTOCOL** (§2 → `periph-stack-usb-thunderbolt-and-wireless`, §3 → `periph-stack-usb-thunderbolt-and-wireless`, §25.1 → `periph-reference`). **A USB-C port can be
>    anything from 480 Mbps and 5 W to 80 Gbps and 240 W with video and PCIe tunnelling.
>    Identical-looking ports and cables behave completely differently, and this single
>    confusion causes more peripheral problems than any technical failure.**
> 2. **⚠️ DESCRIPTORS ARE THE INTERFACE** (§8 → `periph-buses-pcie-hid-keyboards-mice-and-displays`, §19 → `periph-designing-firmware-pcb-and-debugging`). **A USB device declares what it is by
>    handing over a data structure at enumeration. Almost all "device not recognized"
>    problems are descriptor problems, and once you can read descriptors you can debug
>    nearly anything.**
> 3. **⚠️ LATENCY IS A CHAIN, AND PEOPLE OPTIMIZE THE WRONG LINK** (§9 → `periph-buses-pcie-hid-keyboards-mice-and-displays`, §21 → `periph-designing-firmware-pcb-and-debugging`). **Polling
>    rate, debounce, USB scheduling, OS input stack, render queue and display scanout all
>    add up. Buying an 8 kHz mouse while running a 60 Hz display optimizes a link that
>    wasn't the problem.**

---

## §22. Compliance and Certification

**⚠️ Nothing ships without this, and first-time designers routinely underestimate it.**
⚠️ **EMC — emissions and immunity — with FCC Part 15 in the US and CE/UKCA marking in
Europe requiring an EMC directive assessment;** ⚠️ **safety (IEC 62368-1 having replaced
60950 for IT equipment);** ⚠️ **RED for anything with a radio, plus regional radio
approvals.**
**⚠️ Materials and environmental**: ⚠️ **RoHS, REACH, WEEE, and battery regulations.**
**⚠️ Logo programmes**: ⚠️ **USB-IF certification requires membership and testing, and
gives you the right to use the logos and a database listing** (§25.1 → `periph-reference`); ⚠️ **Bluetooth SIG
qualification; DisplayPort and HDMI certification** (§25.2 → `periph-reference`).
**⚠️ Pre-compliance testing** with a cheap near-field probe and spectrum analyser
⚠️ **catches most problems before an expensive chamber booking, and is the single
best-value practice for small teams.**

---

## §23. Accessibility

**⚠️ Peripherals are where accessibility is won or lost**, ⚠️ **because the input device is
the interface for anyone who cannot use a standard keyboard and mouse.**
⚠️ **Switch access and scanning interfaces; ⚠️ modular and adaptive controllers with 3.5 mm
switch jacks; ⚠️ eye tracking; ⚠️ head pointers; ⚠️ alternative keyboards — split,
ortholinear, chorded, one-handed; ⚠️ and braille displays.**
**⚠️ Design practices that cost nothing**: ⚠️ **don't rely on colour alone for status,
support OS accessibility features rather than fighting them, allow full remapping,
make actuation force and travel adjustable where possible, and ⚠️ ensure the device works
without vendor software.**
**⚠️ The mechanical keyboard community's customization work has genuine accessibility
value** — ⚠️ **adjustable actuation, layer systems and macro support serve disability
needs as much as enthusiast ones.**

---

## §24. ⚠️ Peripheral Security

```
⚠️ ⚠️ BADUSB  ⚠️ a device can CLAIM TO BE ANYTHING. ⚠️ A USB stick
   whose firmware declares itself a keyboard can type commands
   at machine speed. ⚠️ THE TRUST MODEL IS THE FLAW: USB has no
   device authentication, and the host believes the descriptor
⚠️ ⚠️ DMA ATTACKS  ⚠️ Thunderbolt and PCIe devices can read host
   memory directly (§7). ⚠️ IOMMU/VT-d and "Thunderbolt security
   levels" exist for this; ⚠️ pre-boot and sleep states have
   been the weak points
⚠️ MALICIOUS CHARGERS AND CABLES  ⚠️ cables with embedded
   implants are commercially available. ⚠️ USB data blockers
   ("USB condoms") and charge-only cables are the mitigation
⚠️ WIRELESS  ⚠️ unencrypted 2.4 GHz keyboard traffic has been
   sniffable and INJECTABLE in documented cases; ⚠️ Bluetooth
   pairing weaknesses recur
⚠️ FIRMWARE  ⚠️ unsigned firmware update paths on peripherals are
   a persistent supply-chain exposure
⚠️ MITIGATIONS  ⚠️ USB device authorization / port control policy ·
   ⚠️ USBGuard on Linux · disable unused ports in firmware ·
   IOMMU enabled · signed firmware · ⚠️ and the plain advice not
   to plug in unknown devices, which remains effective
⚠️ ⚠️ USB4 and USB-C do NOT fix the trust model. ⚠️ They add
   capability, not authentication
```

Attribution

the-vibey-projectthe-vibey-project
View sourceSee grades on GitHubMore from the-vibey-project →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →