Back to skill

Security audit

huawei-cloud-cloudrobo-r2c

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its stated robot-to-cloud purpose, but it can control real robot hardware and transmit telemetry with credentials, so users should review safety and privacy controls before installing.

Install only if you intend to operate a CloudRobo R2C edge client. Use non-production credentials first, keep the credential bundle and private key password protected, start with dummy hardware or dry_run, confirm dry_run still sends observations, clear the robot workspace before live execution, keep an emergency stop available, and install custom adapters only from trusted code.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 290)May include surrounding context.

md
- [Client Config Reference](references/client-config-catalog.md) — client_config.yaml field mapping, Zenoh QoS settings

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/test-cli-commands.sh (reported line 84)May include surrounding context.

sh
--log-level INFO 2>&1 || true
    if [ -f /tmp/r2c_test_observations.pkl ]; then
        echo "  Recording file created: $(ls -la /tmp/r2c_test_observations.pkl)"
        rm -f /tmp/r2c_test_observations.pkl
    else
        echo "  Warning: recording file not created"
    fi

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide documents the contents of the credential bundle, including a private key and device identity metadata, but does not prominently warn users that the zip file and extracted files are highly sensitive secrets. In this R2C/mTLS context, disclosure of server_key.pem or the full bundle could enable impersonation of the robot client or unauthorized access to the data plane.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/cli-installation-guide.md (reported line 112)May include surrounding context.

Option 2: Direct password (avoid on shared shells)

cloudrobo r2c client --bundle ./cert.zip --private-key-password

Option 3: Disable prompting (fail if encrypted)

cloudrobo r2c client --bundle ./cert.zip --no-prompt-password

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instructions tell users to place long-lived Huawei Cloud AK/SK credentials into environment variables without accompanying guidance on secure handling. While environment variables are common, documenting this pattern without warnings can lead to credential exposure through shell history, process inspection, shared environments, CI logs, or accidental persistence in profile files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file explains that observations, joint states, localization, IMU data, heartbeats, and action traffic are published over cloud-connected topics, but it does not include a user-facing warning that these fields may expose operational or sensitive device data. Under the markdown-specific SQP-2 criteria, descriptions of behaviors affecting user data or privacy should disclose those impacts clearly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide documents keyboard bindings that can trigger robot commands like go_home, but it does not place an explicit safety warning near the example to highlight that a key press can cause immediate physical actuation. In a robot-control context, omission of that warning increases the chance of accidental motion, unsafe testing, or operator misuse around live hardware.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The dry-run section tells users to disable dry_run and verify the robot moves correctly, but it does not include a strong safety notice before transitioning from simulated/log-only behavior to real actuator execution. Because this skill directly controls robots, that omission can lead users to run test actions on live hardware without confirming workspace clearance, limits, supervision, or emergency stop readiness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The dry-run section explicitly shows that real hardware observations are still collected and published to Zenoh/cloud while only action execution is suppressed, but it does not prominently warn users about the resulting data exposure. This can mislead operators into believing dry-run is fully non-invasive, causing unintended transmission of potentially sensitive telemetry, sensor data, or robot state to external systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown explains that the runtime can run forever, execute received actions when dry_run is false, and enable keyboard-triggered commands like go_home, but it does not include an explicit safety warning about affecting connected robot hardware or requiring operator caution. For a robotics configuration reference, these behaviors can impact system integrity and physical devices, so the documentation should visibly disclose that actions may move hardware unless dry-run is enabled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation instructs users to record robot observations to a local .pkl file but does not warn that observation data may contain sensitive operational, environmental, or proprietary information. This can lead to unintentional data retention or insecure storage, and the use of pickle also carries downstream risk if such files are later loaded from untrusted sources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest includes commands that use credential bundles, connect a robot-side client to cloud infrastructure, load custom hardware classes, and write logs/recordings, but it does not pair them with explicit safety warnings or execution constraints. In a skill that drives a networked robot edge client, this can lead users or automation to run tests with real credentials, real cloud connections, and potentially real hardware effects without understanding the operational risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This JSON manifest repeatedly labels cases as "type": "write" or "read" but does not define what conditions cause these tests to be selected or excluded. In a manifest file, vague scope markers without explicit constraints can lead to overly broad or unintended invocation behavior by downstream tooling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.