Back to skill

Security audit

huawei-cloud-cloudrobo-robot

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent robot-management guidance, but its bundled verification script can update, export credentials for, and delete a robot without a real confirmation prompt.

Review before installing. Use a least-privilege CloudRobo account, protect HUAWEI_CLOUD_AK/HUAWEI_CLOUD_SK and ~/.cloudrobo/config.yaml, and treat exported certificate ZIPs as credentials. Do not run scripts/test-cli-commands.sh with ROBOT_ID set unless you intend to update, export credentials for, and possibly delete that robot; prefer dry-run and manual commands with explicit confirmations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/test-cli-commands.sh:76
Finding

Verification Script Performs Destructive Cloud Operations Without Enforced Confirmation

Content
View full analysis

Vulnerability Details

File Location: scripts/test-cli-commands.sh, lines 76–98
Vulnerability Type: Destructive authenticated operations without an enforced confirmation gate
Risk Level: High

Vulnerable code:

bash
if [ -n "$ROBOT_ID" ]; then
    echo "Test 6: Show robot detail"
    cloudrobo robot show --robot-id "$ROBOT_ID"
    echo ""

    echo "Test 7: Update robot (user must confirm)"
    echo "WARNING: This updates the robot. Press Ctrl+C to cancel."
    sleep 2
    cloudrobo robot update --robot-id "$ROBOT_ID" --description "Updated by test"
    echo ""

    echo "Test 8: Export access config / certificate (user must confirm)"
    echo "WARNING: This exports the robot access config (zip) with password. Press Ctrl+C to cancel."
    sleep 2
    mkdir -p ./certs
    cloudrobo robot export-certificate --robot-id "$ROBOT_ID" --password "temp-export-pw" --output ./certs || echo "Export may fail if certificate unavailable"
    echo ""

    echo "Test 9: Delete robot (user must confirm)"
    echo "WARNING: This deletes the robot. Press Ctrl+C to cancel."
    sleep 2
    cloudrobo robot delete --robot-id "$ROBOT_ID" || echo "Delete may fail if robot already gone"
    echo ""
fi

Technical Analysis

The documented verification command runs this script directly. If ROBOT_ID is set, the script automatically performs three authenticated write operations against that robot:

  1. It changes the robot description.
  2. It exports the robot access credential bundle.
  3. It irreversibly deletes the robot.

The warning messages and two-second sleeps are not confirmation controls. The script does not read an affirmative response, require a destructive-operation flag, verify an interactive terminal, or default these commands to --dry-run.

This contradicts the Skill's stated control in SKILL.md lines 333–334:

markdown
**Mutating operations** (create/update/delete/expor
...[truncated 1657 chars]
Remediation
View remediation

Remediation Suggestions

  • Make all mutating tests opt-in and default the verification script to read-only or --dry-run.
  • Require a dedicated flag such as --allow-destructive-tests before entering the write-test block.
  • Before each mutation, display the exact robot ID and operation, then require an explicit affirmative response:
    bash
    read -r -p "Delete robot '$ROBOT_ID' permanently? Type the robot ID to confirm: " confirmation
    [ "$confirmation" = "$ROBOT_ID" ] || exit 1
    
  • Fail closed when standard input is not an interactive terminal unless a separately documented noninteractive confirmation mechanism is supplied.
  • Require separate confirmations for update, certificate export, and deletion; do not treat one confirmation as authorization for all operations.
  • Do not use a fixed certificate password. Prompt securely with read -s, accept it through a protected mechanism, or generate a strong random password and disclose it only to the authorized user.
  • Write exported credentials to a user-selected protected directory with restrictive permissions, and clearly report the resulting sensitive file.
  • Keep deletion disabled in routine smoke tests. If cleanup is needed, only delete a robot created by the same test run and verify its recorded identifier immediately before deletion.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This skill explicitly enables export of a robot access-config/certificate bundle, which is a credential artifact used to connect a robot to the platform. Even though the document warns to store it securely, the capability itself facilitates credential extraction to a user-chosen local directory, creating a meaningful risk of credential disclosure or misuse if invoked in an unsafe environment or by an over-privileged agent.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
> **"导出配置文件" = 导出接入配置(证书)**. A robot has **two** configurations:
> - **本体配置(robot body/main config)** — built into `r2c_sdk`, or distributed together with the
>   robot adapter alongside other robots. It is **not** what "download/export config" refers to.
> - **接入配置(access config)** — the robot's access credential bundle used to connect to the
>   platform. This is the one you download/export, and it is produced by `export-certificate`.
>
> The downloaded access config is a **zip** package — treat it as a sensitive credential bundle and

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
record the `service_id` / `exec_model_id`.
4. Pass the `robot_id` and model to `robo-dispatcher`: `cloudrobo dispatch create-task --session-id <sid> --name <name> --task "<task>" --constraints-json '{"model":{"exec_model_id":"<exec_model_id>"},"robot_id":"<robot_id>","exec_constraints":{"max_run_time":10,"max_iter_num":100}}'`.
   > This skill does not call cloudrobo-infer/dispatch by name; the agent orchestrates across
   > skills by first obtaining the robot_id here, then using the infer and dispatch skills.

### Cleanup Workflow (module)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/iam-policies.md (reported line 59)May include surrounding context.

md
| Create robot | Write access to `cloudrobo-service` (`POST /v1/robots`) |
| Show robot detail | Read access to `cloudrobo-service` (`GET /v1/robots/{robot_id}`) |
| Update robot | Write access to `cloudrobo-service` (`PUT /v1/robots/{robot_id}`) |
| Delete robot | Delete access to `cloudrobo-service` (`DELETE /v1/robots/{robot_id}`) |
| Export certificate | Write access to `cloudrobo-service` (`POST /v1/robots/{robot_id}/certificate/export`) |
| Query SDK info | Read access to `cloudrobo-service` (`GET /v1/robots/sdk`) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/robot-config-catalog.md (reported line 76)May include surrounding context.

md
| list_robots | `list_robots(**params)` | `list` | `GET /v1/robots` |
| show_robot | `show_robot(robot_id)` | `show` | `GET /v1/robots/{robot_id}` |
| update_robot | `update_robot(robot_id, req)` | `update` | `PUT /v1/robots/{robot_id}` |
| delete_robot | `delete_robot(robot_id)` | `delete` | `DELETE /v1/robots/{robot_id}` |
| export_robot_certificate | `export_robot_certificate(robot_id, req)` | `export-certificate` | `POST /v1/robots/{robot_id}/certificate/export` |
| show_sdk | `show_sdk()` | `show-sdk` | `GET /v1/robots/sdk` |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/verification-method.md (reported line 87)May include surrounding context.

md
# → Expected click usage error: "not one of arm/humanoid/operation/other/quadruped/wheeled" (exit 2)

# 2. Path traversal rejected via validate_safe_id
cloudrobo robot show --robot-id "../etc/passwd"
# → Expected validation error

# 3. Missing workspace rejected

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · templates/test-vars.json (reported line 102)May include surrounding context.

json
# → Expected click usage error: "not one of arm/humanoid/operation/other/quadruped/wheeled" (exit 2)

# 2. Path traversal rejected via validate_safe_id
cloudrobo robot show --robot-id "../etc/passwd"
# → Expected validation error

# 3. Missing workspace rejected

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
it.
3. **Store securely** — After export, place the downloaded zip under secure storage (a protected
   directory, secret manager, or the robot-side onboarding location). Do not leave it in a shared /
   world-readable path. This zip is consumed on the robot side (e.g. by `r2c_sdk` / the R2C client)
   together with the body config already carried inside the SDK or adapter.
4. **Feedback** — Prompt the user that the access-config zip was written to the specified file, and
   that it can be used for robot-side access configuration (e.g. with `r2c_sdk.cloudroboclient`).

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs users to place long-lived AK/SK credentials in environment variables or persist them in a local config file, but it does not warn about shell history exposure, process/environment leakage, file-permission risks, or the preference for short-lived credentials and secret managers. In a CLI used to manage robots and export certificates, compromise of these credentials could enable unauthorized access to CloudRobo resources and related cloud operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The diagram explicitly describes exporting a robot access certificate/config ZIP and writing it to disk, but the only security note is a brief 'store securely' statement after the write. For a skill that manages physical robots and secure access material, under-documenting the sensitivity of exported credentials can lead users to save secrets in unsafe locations, increasing risk of credential theft and unauthorized robot access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation states that the default region is cn-southwest-2 and only later mentions overriding it via config, which effectively bakes in a locale-specific default without explicit user opt-in or justification. Under the policy, region or locale constraints should either be optional by default, justified, or clearly presented as a user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The phrase '下载/导出配置文件' appears inline as part of the user request description, introducing a specific language variant without any opt-in or explanation. Under the stated policy, forcing or assuming a language/locale without user choice can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Lines L38-L40 introduce non-English terms such as '本体配置', '接入配置', and '下载/导出配置文件' inline in an otherwise English reference document. This can impose a language expectation on users without opt-in or justification, which fits the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file title and explanatory note are entirely in Chinese, with no indication that language selection is optional or that the document is intentionally limited to a Chinese-speaking audience. Under the stated policy, fixed language usage without user opt-in can be a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.