Back to skill

Security audit

huawei-cloud-cloudrobo-dispatch

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent and disclosed, but its packaged verification script can submit a real robot movement task after only a brief warning, without affirmative confirmation.

Review this skill carefully before installing. It needs CloudRobo credentials and can create, wait on, cancel, and read robot tasks in a workspace. Do not run scripts/test-cli-commands.sh against a real robot unless you are prepared for it to submit the hardcoded movement task; prefer dry-run commands, a simulator, or an isolated test robot, and require an explicit yes prompt before any create-task or cancel-task operation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/test-cli-commands.sh:59
Finding

Verification Script Dispatches a Physical Robot Task Without Affirmative Confirmation

Content
View full analysis

Vulnerability Details

File Location: scripts/test-cli-commands.sh, lines 59–70
Vulnerability Type: Missing confirmation gate for a physical, side-effecting operation
Risk Level: Medium

Vulnerable Code

bash
# Test 5: Create task (mutating, needs confirmation)
if [ -z "$TASK_ID" ]; then
    if [ -n "$ROBOT_ID" ] && [ -n "$EXEC_MODEL_ID" ]; then
        echo "Test 5: Create task (mutating)"
        echo "WARNING: This creates a dispatcher task. Press Ctrl+C to cancel."
        sleep 2
        CREATE_RESULT=$(cloudrobo dispatch create-task \
            --session-id "$SESSION_ID" \
            --name "test-task-$(date +%s)" \
            --task "Move forward 1 meter and report position" \
            --constraints-json "{\"model\":{\"exec_model_id\":\"$EXEC_MODEL_ID\"},\"robot_id\":\"$ROBOT_ID\",\"exec_constraints\":{\"max_run_time\":10,\"max_iter_num\":100}}")

Technical Analysis

The script labels task creation as requiring confirmation, but implements only a warning followed by a two-second delay. Unless the operator interrupts the process, it automatically submits a real task through the authenticated cloudrobo CLI.

This is not an affirmative confirmation mechanism. It is also ineffective in unattended execution, where no operator may be present to press Ctrl+C. The task text is hardcoded to direct the selected robot to move forward one meter.

The issue is reachable when:

  1. SESSION_ID is set.
  2. ROBOT_ID and EXEC_MODEL_ID are set.
  3. TASK_ID is unset.
  4. The verification script is executed.

The documented safety model requires confirmation before task creation. Specifically, SKILL.md lines 350–351 and 434, references/verification-method.md lines 9–10, and the confirmation sequence in references/dataflow-diagram.md lines 32–34 all require user confirmation. The executable script does not enforce that requirement.

Attack Path

  1. An operator configures valid CloudRobo credentials and environment variable ...[truncated 1435 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make verification non-mutating by default and invoke create-task with --dry-run.
  2. Require an explicit opt-in flag, such as --execute-mutating-tests, before submitting any real task.
  3. Add an affirmative interactive prompt that identifies the exact session, robot, execution model, and movement instruction. Continue only after an unambiguous response such as yes.
  4. Refuse real task creation in non-interactive environments unless a separate, explicit authorization mechanism is supplied.
  5. Prefer a dedicated simulator or clearly isolated test robot for lifecycle tests.
  6. Preserve the existing execution limits, but do not treat them as a substitute for confirmation.
  7. Ensure the executable behavior matches the confirmation requirements documented in SKILL.md and the reference documents.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (15)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/dataflow-diagram.md (reported line 74)May include surrounding context.

md
A->>U: confirm cancellation (mutating op)
    U-->>A: confirm
    A->>CLI: cancel-task --session-id <sid> --task-id <tid>
    CLI->>S: DELETE /v1/robo-dispatcher/sessions/{sid}/tasks/{tid}
    S->>D: request cancellation
    D-->>S: task transitioned to terminal (cancelled)
    S-->>CLI: JSON

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/iam-policies.md (reported line 55)May include surrounding context.

md
| List tasks | Read access to `cloudrobo-service` (`GET /v1/robo-dispatcher/sessions/{session_id}/tasks`) |
| Show task | Read access to `cloudrobo-service` (`GET /v1/robo-dispatcher/sessions/{session_id}/tasks/{task_id}`) |
| Wait for task (`wait-task`) | Same read access as show-task — `wait-task` is a client-side polling helper that repeatedly `GET`s the task (`GET /v1/robo-dispatcher/sessions/{session_id}/tasks/{task_id}`); no additional permission |
| Cancel task | Write access to `cloudrobo-service` (`DELETE /v1/robo-dispatcher/sessions/{session_id}/tasks/{task_id}`) |
| Show task result | Read access to `cloudrobo-service` (`GET /v1/robo-dispatcher/sessions/{session_id}/tasks/{task_id}/result`) |
| Resolve robot (cross) | Read access to `cloudrobo-service` robot list/show |
| Resolve exec model (cross) | Read access to `cloudrobo-asset-manager` / infer service |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/verification-method.md (reported line 62)May include surrounding context.

md
| Test | Command | Expected |
| ------ | ------- | ---------- |
| Path traversal | `cloudrobo dispatch show-task --session-id <sid> --task-id '../etc/passwd'` | Blocked by `validate_safe_id` — error raised |
| Missing session_id | `cloudrobo dispatch create-task` without `--session-id` | CLI requires the parameter; clear usage error |
| Invalid session_id | `cloudrobo dispatch list-tasks --session-id 'nonexistent'` | Appropriate not-found / validation error |
| Dry-run create | `cloudrobo dispatch create-task --... --dry-run` | Shows what would be created; no task submitted |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/test-cli-commands.sh (reported line 124)May include surrounding context.

sh
| Test | Command | Expected |
| ------ | ------- | ---------- |
| Path traversal | `cloudrobo dispatch show-task --session-id <sid> --task-id '../etc/passwd'` | Blocked by `validate_safe_id` — error raised |
| Missing session_id | `cloudrobo dispatch create-task` without `--session-id` | CLI requires the parameter; clear usage error |
| Invalid session_id | `cloudrobo dispatch list-tasks --session-id 'nonexistent'` | Appropriate not-found / validation error |
| Dry-run create | `cloudrobo dispatch create-task --... --dry-run` | Shows what would be created; no task submitted |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · templates/test-vars.json (reported line 102)May include surrounding context.

json
| Test | Command | Expected |
| ------ | ------- | ---------- |
| Path traversal | `cloudrobo dispatch show-task --session-id <sid> --task-id '../etc/passwd'` | Blocked by `validate_safe_id` — error raised |
| Missing session_id | `cloudrobo dispatch create-task` without `--session-id` | CLI requires the parameter; clear usage error |
| Invalid session_id | `cloudrobo dispatch list-tasks --session-id 'nonexistent'` | Appropriate not-found / validation error |
| Dry-run create | `cloudrobo dispatch create-task --... --dry-run` | Shows what would be created; no task submitted |

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/dataflow-diagram.md (reported line 142)May include surrounding context.

md
#!/bin/bash
# Test script for cloudrobo-dispatch skill
# Usage: ./test-cli-commands.sh
# Requires: a valid SESSION_ID, and for full lifecycle tests, a test ROBOT_ID and EXEC_MODEL_ID.
# Optional env vars:

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/iam-policies.md (reported line 47)May include surrounding context.

md
#!/bin/bash
# Test script for cloudrobo-dispatch skill
# Usage: ./test-cli-commands.sh
# Requires: a valid SESSION_ID, and for full lifecycle tests, a test ROBOT_ID and EXEC_MODEL_ID.
# Optional env vars:

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/test-cli-commands.sh (reported line 2)May include surrounding context.

sh
#!/bin/bash
# Test script for cloudrobo-dispatch skill
# Usage: ./test-cli-commands.sh
# Requires: a valid SESSION_ID, and for full lifecycle tests, a test ROBOT_ID and EXEC_MODEL_ID.
# Optional env vars:

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/test-cli-commands.sh (reported line 20)May include surrounding context.

sh
#!/bin/bash
# Test script for cloudrobo-dispatch skill
# Usage: ./test-cli-commands.sh
# Requires: a valid SESSION_ID, and for full lifecycle tests, a test ROBOT_ID and EXEC_MODEL_ID.
# Optional env vars:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains very broad phrases such as "dispatch," "agent task," "cancel task," and generic Chinese equivalents that could match ordinary user conversation and cause the skill to activate outside its intended context. Because this skill can create or cancel real robot tasks, over-broad activation increases the chance of unintended invocation of mutating operations, especially in multi-skill agent environments.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
## Overview

The `cloudrobo-dispatch` skill manages **embodied task dispatch** via the `robo-dispatcher`
service. It lets the agent create a task that runs on a robot (identified by `robot_id`) under
an execution model (`exec_model_id`) inside a session (`session_id`), monitor it, cancel it, and
retrieve the natural-language task result plus log items.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The scope explicitly says the skill validates six operations including wait-task. The manifest description enumerates create embodied tasks, list/show tasks, cancel tasks, and retrieve task results, but does not include waiting/polling as a supported operation, so the documentation materially expands the advertised intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest states the skill manages task dispatch by creating tasks, listing/showing them, cancelling them, and retrieving results. This document instructs use of an additional wait-task operation and later treats it as one of the supported dispatcher operations, which goes beyond the described capability set and creates a documentation-to-stated-intent mismatch.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/verification-method.md (reported line 67)May include surrounding context.

md
| Invalid session_id | `cloudrobo dispatch list-tasks --session-id 'nonexistent'` | Appropriate not-found / validation error |
| Dry-run create | `cloudrobo dispatch create-task --... --dry-run` | Shows what would be created; no task submitted |
| Dry-run cancel | `cloudrobo dispatch cancel-task --session-id <sid> --task-id <tid> --dry-run` | Shows what would be cancelled; no action taken |
| Confirm gate | create-task / cancel-task without confirmation | Agent prompts user before execution |

## Expected Results Matrix

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file documents show-task-result returning {task, log_items} and the agent printing and summarizing the result, but it does not warn that logs or task details can contain sensitive operational or user data. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect user data or privacy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.