Back to skill

Security audit

Sphero Mini Control

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Sphero Mini control purpose, but its documentation includes unsafe setup paths that download unpinned remote Python code and grant broad or persistent privileges.

Review this skill carefully before installing. The bundled Sphero control code appears purpose-aligned, but avoid following the docs that curl Python files from GitHub master, avoid running examples with sudo, and do not apply setcap to the system python3 binary. Use only reviewed local code, keep the robot supervised in a clear area, and treat pet-play mode as physical device motion that can collide with people, pets, stairs, cords, or fragile items.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/examples.md:7
Finding

Unpinned Remote Python Payload Retrieval and Execution

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/troubleshooting.md:176
Finding

Persistent Network Capabilities Granted to the Global Python Interpreter

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The code clearly matches the core purpose of controlling a Sphero Mini robot: it wakes/sleeps the device, changes LED color, rolls it, and reads battery and sensor data. There is no sign of unrelated or risky undeclared behavior. However, the declared description claims additional capabilities not present in the supplied code chunk, notably drawing shapes and 'play with cats.' It also specifically says the skill uses bleak for cross-platform BLE support, but this snippet only imports and uses a sphero_mini wrapper, so that implementation detail is not supported by the visible code. Because the supplied code only partially covers the declared functionality, the description does not accurately represent this code chunk in full.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README promotes autonomous random movement around pets ('Cat Play Mode') without providing basic physical safety guidance such as clearing obstacles, supervising use, avoiding stairs, and preventing contact with fragile items or unsafe pet behavior. In a skill that controls a moving physical device, omission of safety warnings can contribute to collisions, property damage, or minor injury to pets or people.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation promotes random physical robot movement for 'cat play mode' without clearly warning users to ensure a safe, obstacle-free area and supervise pets. Because this controls a real moving device, unpredictable motion can cause minor injury, property damage, or distress to pets if used in confined or unsafe environments.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 17)May include surrounding context.

  1. Check MAC address:
    bash
    # Linux
    sudo hcitool lescan
    
    # Look for "SM-XXXX" device
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 29)May include surrounding context.

  1. Check MAC address:
    bash
    # Linux
    sudo hcitool lescan
    
    # Look for "SM-XXXX" device
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 32)May include surrounding context.

  1. Check MAC address:
    bash
    # Linux
    sudo hcitool lescan
    
    # Look for "SM-XXXX" device
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 168)May include surrounding context.

  1. Check MAC address:
    bash
    # Linux
    sudo hcitool lescan
    
    # Look for "SM-XXXX" device
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 181)May include surrounding context.

  1. Check MAC address:
    bash
    # Linux
    sudo hcitool lescan
    
    # Look for "SM-XXXX" device
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
85% confidence
Finding

The guidance to run the example script with sudo encourages executing the entire Python program as root. If the script, its dependencies, or imported modules are modified or compromised, this would grant full system privileges and significantly increase the blast radius of any bug or malicious code.

Content

Scanner excerpt · references/troubleshooting.md (reported line 180)May include surrounding context.

Solution:

bash
# Run with sudo
sudo python3 example_roll.py XX:XX:XX:XX:XX:XX

# OR give capabilities to Python

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
89% confidence
Finding

sudo setcap 'cap_net_raw,cap_net_admin+eip' $(which python3) grants broad network-related capabilities to the system Python interpreter. This affects every Python script launched with that interpreter, making any future Python execution more privileged than expected and expanding the impact of malicious packages, imports, or local script hijacking.

Content

Scanner excerpt · references/troubleshooting.md (reported line 184)May include surrounding context.

sudo python3 example_roll.py XX:XX:XX:XX:XX:XX

OR give capabilities to Python

sudo setcap 'cap_net_raw,cap_net_admin+eip' $(which python3)

text

## General Tips

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script immediately connects to the robot and issues movement commands that cause physical motion without any user confirmation, safety prompt, or environment check. In a BLE-controlled robot context, this can lead to unintended movement, collisions, falls from edges, or harm to nearby objects, pets, or fingers if the script is run accidentally or against the wrong device.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The module docstring includes a Chinese-only mode label alongside English, and later runtime messages continue this bilingual/localized wording without any user-configurable language selection. Under the stated policy, hardcoded language behavior can be a locale-policy issue when the skill does not offer opt-in or explain why a specific locale is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file includes user-facing natural-language strings in both English and Chinese, such as the docstring and progress message, without indicating whether the user prefers that locale mix. This can violate language/locale policy expectations when a skill presents a specific language choice without user opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.