Back to skill

Security audit

FlexArm Robot Arm: Physical Tap, Swipe, OCR for Real Phones

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for robot phone automation, but it asks users to run a powerful persistent Windows control service with administrator setup and weakly documented access controls.

Review before installing. Only install from a source you trust, verify the downloaded binaries independently if possible, and run the administrator setup only on a machine where a persistent robot-control service is acceptable. Keep the phone supervised, avoid sensitive apps or screens unless necessary, and treat screenshots and YAML scripts as potentially sensitive local data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:53
Finding

Unverified Privileged Binary Dependency and Service Installer

Content
View full analysis
**Note**: First-time use requires Administrator privileges to install the Windows service. Run `RobotArmServer.exe` **as Administrator**. In daily use, administrator rights are not needed if the service is already installed. > If service installation fails, the program still starts but the arm is unavailable. You can manually run `robot-arm-service\安装.bat` as Administrator to install the service. ``` ### Technical Analysis The Skill depends on large precompiled executables downloa ...[truncated 2523 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:673
Finding

Sensitive Robot and Smartphone Control API Lacks Documented Authentication

Content
View full analysis
` | Read/update app page config | | 53 | GET/PUT | `/api/config/gesture` | Read/update gesture config | | 54 | POST | `/api/shutdown` | Graceful service shutdown | ``` Example requests contain no authentication credential: ```bash curl -X POST http://127.0.0.1:7826/api/click \ -H "Content-Type: application/json" \ -d '{"x": 0.5, "y": 0.5}' ``` ```bash curl -X POST http://127.0.0.1:7826/api/run_script \ -H "Content-Type: application/json" \ -d '{"path": "scripts/hello_flexarm.yaml"}' ``` ### Technical Analysis The documented API controls a physical robot arm and camera, captures smartphone screenshots, executes automation scripts, changes persistent configurations, and shuts down the service. However, the API description and examples do not specify an authentication token, session mechanism, client certificate, operating-system peer validation, or endpoint-level authorization policy. Binding the service to `127.0.0.1` reduces direct network exposure but does not establish a security boundary between local applications. Any proce ...[truncated 2390 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill enables direct physical interaction with a real smartphone, including clicks, swipes, app launches, typing, and script execution, but the documentation does not clearly warn that these actions can trigger unintended or irreversible effects such as purchases, message sends, account changes, or device misconfiguration. In a physical-control context, omission of such warnings meaningfully raises safety and security risk because an autonomous agent can act on the user's real device state.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
The port is fixed at 7826 and cannot be changed. Flask's default port 5000 does not apply.

## Important: Chinese Characters in curl

**Do NOT use curl to send Chinese characters in JSON.** curl corrupts UTF-8 encoding and the server won't correctly recognize Chinese keywords, causing lookup failures.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

curl -X POST http://127.0.0.1:7826/api/find_text -d '{"text_keyword":"领取"}'

✅ Correct: use Python requests for Chinese parameters

python -c "import requests; r = requests.post('http://127.0.0.1:7826/api/find_text', json={'text_keyword': '领取'}); print(r.text)"

text

APIs with English-only parameters (e.g., `detect_desktop`, `click_icon`, `run_script`, `click_at`) may use curl. APIs involving Chinese keywords (`find_text`, `click_text`, `detect_page` page names) **must** use Python.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1225)May include surrounding context.

curl -X POST http://127.0.0.1:7826/api/find_text -d '{"text_keyword":"领取"}'

✅ Correct: use Python requests for Chinese parameters

python -c "import requests; r = requests.post('http://127.0.0.1:7826/api/find_text', json={'text_keyword': '领取'}); print(r.text)"

text

APIs with English-only parameters (e.g., `detect_desktop`, `click_icon`, `run_script`, `click_at`) may use curl. APIs involving Chinese keywords (`find_text`, `click_text`, `detect_page` page names) **must** use Python.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

curl -X POST http://127.0.0.1:7826/api/find_text -d '{"text_keyword":"领取"}'

✅ Correct: use Python requests for Chinese parameters

python -c "import requests; r = requests.post('http://127.0.0.1:7826/api/find_text', json={'text_keyword': '领取'}); print(r.text)"

text

APIs with English-only parameters (e.g., `detect_desktop`, `click_icon`, `run_script`, `click_at`) may use curl. APIs involving Chinese keywords (`find_text`, `click_text`, `detect_page` page names) **must** use Python.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

curl -X POST http://127.0.0.1:7826/api/find_text -d '{"text_keyword":"领取"}'

✅ Correct: use Python requests for Chinese parameters

python -c "import requests; r = requests.post('http://127.0.0.1:7826/api/find_text', json={'text_keyword': '领取'}); print(r.text)"

text

APIs with English-only parameters (e.g., `detect_desktop`, `click_icon`, `run_script`, `click_at`) may use curl. APIs involving Chinese keywords (`find_text`, `click_text`, `detect_page` page names) **must** use Python.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 1225)May include surrounding context.

curl -X POST http://127.0.0.1:7826/api/find_text -d '{"text_keyword":"领取"}'

✅ Correct: use Python requests for Chinese parameters

python -c "import requests; r = requests.post('http://127.0.0.1:7826/api/find_text', json={'text_keyword': '领取'}); print(r.text)"

text

APIs with English-only parameters (e.g., `detect_desktop`, `click_icon`, `run_script`, `click_at`) may use curl. APIs involving Chinese keywords (`find_text`, `click_text`, `detect_page` page names) **must** use Python.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 262)May include surrounding context.

Step 2: Test connectivity

bash
curl http://127.0.0.1:7826/api/health
# Returns: {"ok": true, "data": {"status": "running", ...}}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly supports capturing, returning, and storing smartphone screenshots, including historical screenshot listing, but does not warn about sensitive on-screen data such as messages, credentials, financial information, or tokens. Because this is a real-phone automation skill, screenshot retention materially increases privacy and data-exposure risk if users or agents save images by default or leave them on disk.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The script engine can auto-execute a default branch when page detection fails, meaning the system may continue taking actions even when state recognition is uncertain. In a real-device physical automation context, acting on an unverified UI state can cause unintended taps, navigation, or workflow continuation on the wrong screen.

Content

Scanner excerpt · SKILL.md (reported line 475)May include surrounding context.

features: []

text

> When `switch_page` in a script doesn't match any page, it auto-executes the `default` branch — no separate config needed.

### How to Create Icon Templates

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · SKILL.md (reported line 1181)May include surrounding context.

md
| `"error": "Script is running"` | A script is executing in the background | Check `script_status`, wait for completion, or call `stop_script` |
| `"error": "RobotActions not initialized"` | Arm not connected / service not started | Guide user to check `robot-arm-service\安装.bat` |
| `"error": "Missing parameter: path"` | Incomplete request parameters | Check API call parameters |
| `"ok": false, "data": null` (find_template) | Icon not found | Lower `threshold` or check icon file, **do not retry indefinitely** |
| `"ok": false, "data": null` (find_text) | OCR text not found | Widen `roi` or lower `min_score`, try at most 2-3 times then report |
| `"error": "Unauthorized"` | License check failed | Guide user to activate |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1200)May include surrounding context.

Step 1: Check service status

bash
curl http://127.0.0.1:7826/api/health
# Returns: {"ok":true,"data":{"status":"running","arm_connected":true,...}}

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1225)May include surrounding context.

Step 5: Wait for app launch, detect page

bash
python -c "import requests,time; time.sleep(2)"
python -c "import requests; r=requests.post('http://127.0.0.1:7826/api/detect_page',json={'config_path':'scripts/configs/app_qishui.yaml'}); print(r.text)"
# Returns: {"ok":true,"data":{"page_name":"Music","score":0.85,"matched":true}}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown includes special instructions for Chinese characters and repeatedly uses Chinese-specific examples and parameters, effectively steering usage toward a specific locale. It does not clearly state that the skill is limited to Chinese-language device flows nor offer any user opt-in or alternative for other languages/locales.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.