Back to skill

Security audit

Ecovacs Mcp

Security checks for vulnerabilities and agentic risk

Overview

This skill is understandable and not malicious, but it can control a real home robot vacuum through an unpinned external MCP package with broad activation language and no clear pre-action confirmation requirement.

Install only if you are comfortable giving the MCP server your Ecovacs API key and allowing your assistant to control a physical vacuum. Confirm robot-specific intent before start, stop, pause, resume, or dock commands, especially for short or ambiguous requests, and prefer pinning or otherwise verifying the ecovacs-robot-mcp package before running it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Third-Party Package Is Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:16-17, 25-26, 91; equivalent instructions also appear in prompt_context.md:7-8, 16-17, 84, skill.toml:8-9, 17-18, 86, and README.md:16, 42-43
Vulnerability Type: Unpinned runtime dependency
Risk Level: Medium

Vulnerable Code

markdown
- **`uvx`** (recommended) or `python3` with `ecovacs-robot-mcp` installed
json
{
  "ecovacs_mcp": {
    "command": "uvx",
    "args": ["--from", "ecovacs-robot-mcp", "python", "-m", "ecovacs_robot_mcp"],
    "env": {
      "ECO_API_KEY": "YOUR_API_KEY",
      "ECO_API_URL": "https://open.ecovacs.com"
    }
  }
}
markdown
- **Server won't start** — ensure `uvx` is available (`pip install uv`), or install directly: `pip install ecovacs-robot-mcp`

Technical Analysis

The documented uvx command resolves and executes ecovacs-robot-mcp without an exact version constraint, integrity hash, lock file, or signed-provenance verification. The fallback pip install command is similarly unpinned.

As a result, the code executed during future installations can differ from the dependency version that existed when this Skill was reviewed. The downloaded MCP process also receives ECO_API_KEY through its environment and is expected to interact with account-bound physical devices. The project itself contains only prompt and metadata files, so the effective runtime implementation is outside the audited artifact.

This is a supply-chain exposure rather than evidence that the current external package is malicious. Describing the associated repository as official does not ensure that package resolution will always produce a previously audited artifact.

Attack Path

  1. An attacker compromises the package publisher, package-index account, release process, or another relevant dependency-distribution component.
  2. The attacker publishes a malicious or backdoored release under the package name ecovacs-robot-mcp.
  3. A user follows the documented ...[truncated 1172 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin ecovacs-robot-mcp to a specific, reviewed version in both uvx and installation examples.
  2. Verify package integrity using hashes from a committed lock file or equivalent reproducible dependency mechanism.
  3. Prefer signed releases and verify package provenance before execution.
  4. Document a controlled upgrade process that reviews dependency changes before updating the pinned version.
  5. Run the MCP server under a dedicated, unprivileged account or sandbox with minimal filesystem and network access.
  6. Use a narrowly scoped, revocable API key where the Ecovacs platform supports such restrictions.
  7. Avoid exposing unrelated credentials to the MCP process and ensure environment variables are not logged.
  8. Keep the package name, pinned version, and integrity metadata consistent across SKILL.md, prompt_context.md, skill.toml, and README.md.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README encourages commands that immediately control a physical robot vacuum but does not warn users that actions like starting cleaning or sending the robot to dock can have real-world effects. In a home environment, unexpected robot movement can create safety, privacy, or property-interference risks, especially around pets, children, obstacles, or sensitive areas.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description contains broad trigger phrases such as general requests to vacuum, mop, clean the house, or check charging status, even when the user does not explicitly mention Ecovacs. In an agent-routing context, this can cause the skill to activate on ambiguous household-cleaning requests and issue real-world device control actions to a user's robot vacuum without sufficiently specific intent confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill controls a physical device but the description and top-level guidance do not prominently warn that using it can trigger real-world actions like starting cleaning or sending the robot to dock. Without an upfront warning and confirmation expectation, users or orchestrators may treat it like a read-only informational skill, increasing the risk of unintended physical actions in the home.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger mapping is broad enough to overlap with common household language such as 'clean the floor', 'stop', or 'charge', which can cause the skill to activate when the user did not intend to control a robot vacuum. Because this skill performs real-world actions on a physical device, unintended invocation can start, pause, or redirect the robot without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description does not clearly warn that it can directly control a physical device inside the user's home. Lack of transparency increases the chance that users or downstream agents invoke it casually, without appreciating that it may start movement, stop cleaning, or send the robot to dock.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language mapping uses vague phrases such as 'stop', 'pause', 'dock', and 'charge' without contextual constraints, making accidental activation more likely. In a physical-control skill, ambiguous mappings are more dangerous because they can directly start, pause, or move a household device based on underspecified user input.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest advertises battery-status functionality that is not supported by the documented tools, creating a capability mismatch. In a home-device control skill, this can mislead the agent or user into making decisions based on nonexistent telemetry, potentially causing unsafe or unintended physical-device actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description is overly broad and can trigger the skill on generic phrases like 'clean the house' even when the user may not mean controlling a robot vacuum. Because this skill can issue real commands to a physical device, over-triggering increases the risk of unintended actuation in the user's home.

Content

No source excerpt is available for this finding.

Rp1

Low
Category
MCP Rug Pull
Confidence
60% confidence
Finding

pip install without ==version installs the latest release, which could include malicious changes.

Content

No source excerpt is available for this finding.

Rp1

Low
Category
MCP Rug Pull
Confidence
60% confidence
Finding

pip install without ==version installs the latest release, which could include malicious changes.

Content

No source excerpt is available for this finding.

Rp1

Low
Category
MCP Rug Pull
Confidence
60% confidence
Finding

pip install without ==version installs the latest release, which could include malicious changes.

Content

No source excerpt is available for this finding.

Rp1

Low
Category
MCP Rug Pull
Confidence
60% confidence
Finding

pip install without ==version installs the latest release, which could include malicious changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.