Back to skill

Security audit

ecovacs-skills-deebot-control

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Ecovacs robot-control helper, but its access-key handling is risky enough to require review before installation.

Install only if you understand that the AK can control your Ecovacs robots. Prefer using a trusted HTTPS Ecovacs or self-hosted gateway, avoid placing the AK in chat, shell history, or URLs, prefer the POST device-list form, protect or avoid ~/.ecovacs_session.json, and rotate the AK if it may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ecovacs.py:80
Finding

Access Key Exposed in URL Query String

Content
View full analysis
`. 3. A gateway, reverse proxy, monitoring product, or diagnostic logger records the complete request URL. 4. An attacker or unauthorized operator gains read access to those logs. 5. The attacker extracts the AK from the query string. 6. The attacker submits the AK to the device-list and control endpoints. 7. Subject to the AK's permissions, the attacker discovers associated robots and remotely issues cleaning, docking, or other supported commands. ### Impact Assessment Successful exploitation exposes the privileges gran ...[truncated 520 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ecovacs.py:53
Finding

Plaintext Access Key File Created Without Restrictive Permissions

Content
View full analysis
`. 2. The process runs with a permissive umask, or `~/.ecovacs_session.json` already exists with broad permissions. 3. The script writes the plaintext AK without enforcing mode `0600`. 4. Another local account or compromised process reads the session file. 5. The attacker extracts the AK. 6. The attacker reuses the key against the configured or official Ecovacs gateway. 7. The attacker obtains the robot-control capabilities authorized by that AK. ### Impact Assessment Exploitation requires local filesystem access under conditions that allow reading the file. A stolen AK may grant remote access to associated robot metadata and control functions. The vulnera ...[truncated 215 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ecovacs.py:32
Finding

Unvalidated Gateway Override Can Exfiltrate the Access Key or Permit Plaintext Transport

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:12
Finding

Documentation Encourages Access Key Submission Through Command Arguments and Chat

Content
View full analysis
# writes ~/.ecovacs_session.json with {"ak":"..."} only ``` The script accepts the literal AK from `argv`: ```python if cmd == "set-ak": if len(args) < 2: print("Usage: python3 ecovacs.py set-ak ") sys.exit(1) save_ak(args[1]) sys.exit(0) ``` ### Technical Analysis Command-line arguments may be recorded in shell history and can be visible through process-inspection facilities while the process is running. Environment variables may also be exposed to child processes, crash reports, debugging tools, or same-user process inspection on some systems. Entering an AK into an AI chat can retain it in conversation history, telemetry, exports, support records, browser storage, or service-side logs. The instruction unnecessarily normalizes disclosure of a credential through channels that may have broader retention and access than a dedicated secret store. ### Attack Path 1. A user follows the documented setup instructions. 2. The user enters the literal AK in a shell command or sends it through a chat conversation. 3. The key is retained in shell history, process metadata, chat history, telemetry, or exported records. 4. Another local user, account operator, compromised extension, or party with access to retained records retrieves the key. 5. The attacker submits the key to the Ecovacs gateway. 6. ...[truncated 520 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tainted flow: 'req' from os.environ.get (line 70, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/ecovacs.py (reported line 64)May include surrounding context.

python
def http_get_json(url):
    req = urlreq.Request(url, headers={"Accept": "application/json"})
    with urlreq.urlopen(req, timeout=45) as resp:
        return json.loads(resp.read().decode("utf-8"))

Tainted flow: 'req' from os.environ.get (line 70, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/ecovacs.py (reported line 75)May include surrounding context.

python
def http_get_json(url):
    req = urlreq.Request(url, headers={"Accept": "application/json"})
    with urlreq.urlopen(req, timeout=45) as resp:
        return json.loads(resp.read().decode("utf-8"))

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents capabilities that rely on environment variables, local file writes, and outbound network access, but it does not declare any explicit tool scope or permissions boundary. This increases the chance an agent can use broader-than-expected capabilities, making secret handling and external API actions less auditable and easier to misuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The documented curl example sends the access key in a URL query string, which can be exposed through shell history, proxy logs, browser/server logs, monitoring tools, and referrer-like telemetry. Because the AK authorizes control of the user's vacuum account devices, leakage could let another party enumerate devices and issue commands via the API.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

Device list

bash
curl -sS "${BASE_URL}/robot/skill/deviceList?ak=YOUR_AK"

Control: POST /robot/skill/ctl with JSON ak, optional nickName (fuzzy match on list), and ctl.cmd / ctl.data.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/agent-internal.md (reported line 26)May include surrounding context.

bash
# 1) Area list (list[].mssid)
curl -sS -X POST "${BASE_URL}/robot/skill/ctl" -H 'Content-Type: application/json' \
  -d "{\"ak\":\"${AK}\",\"nickName\":\"device-nick-fragment\",\"ctl\":{\"cmd\":\"GetAreaList\",\"data\":{}}}"

# 2) Zone clean: Clean(type=spotarea) + aid=[mssid...]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explicitly recommends sending completion summaries and abnormal-end notifications to external channels like Feishu, but it does not warn about minimizing or sanitizing the content sent. Those summaries may include device status, usage patterns, battery level, area cleaned, and timing data, which can disclose occupancy and household behavior to third-party systems if routed insecurely or too broadly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The example sends the access key in a URL query string (?ak=YOUR_AK) to a remote endpoint. Secrets placed in URLs are commonly exposed via logs, browser/history artifacts, reverse proxies, monitoring systems, and referrer-like telemetry, increasing the chance of credential leakage and subsequent unauthorized device access.

Content

Scanner excerpt · references/api.md (reported line 22)May include surrounding context.

Prefer GET:

bash
curl -sS "${BASE_URL}/robot/skill/deviceList?ak=YOUR_AK"

Example response:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file documents commands that start cleaning, send the robot to charge, and stop a charge-return sequence, all of which can affect the user's physical device and environment. The section provides direct invocation examples but does not include a caution or user-facing warning about initiating device actions, despite SQP-2 applying to markdown files when behavior may affect user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script persists the Ecovacs access token to ~/.ecovacs_session.json in plaintext and does not set restrictive file permissions. On multi-user systems or environments with weak home-directory protections, local attackers or other processes could read the token and gain unauthorized control over the user’s vacuum devices via the cloud API.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

文件标题区将当前文档固定为“中文”,正文也完全以中文撰写,未说明用户可选择其他语言版本或由系统按用户偏好决定。按规则,强制特定语言且无用户选择/opt-in 的自然语言约束可构成语言策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title and introductory text explicitly label the API reference and internal heuristics as English, which indicates a fixed language choice. There is no accompanying note offering language choice or explaining that English is required for a justified region-specific reason, so this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.