Back to skill

Security audit

S2-SWM Boundary Scanner Engine(动态边界扫描器)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed boundary-scanning/simulation tool for embodied-AI spatial perception and does not show hidden data access, persistence, or actuation authority.

Installers should treat this as an advisory perception/simulation skill, not a complete robotics safety system. If used with real robots, keep movement control, actuator authorization, sensor access, and safety interlocks in separate, explicit components.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
78% confidence
Finding
The whitepaper states that outputs integrate with upstream LLM reasoning modules and downstream kinematic inverse solvers, which broadens the skill from passive sensing into potential decision and actuation pipelines. In an embodied AI context, ambiguous coupling between perception, reasoning, and motion can increase the risk of unsafe autonomy, hidden data flow to external modules, or unintended physical actions if implementers assume these integrations are sanctioned.

Context-Inappropriate Capability

Medium
Confidence
79% confidence
Finding
The Chinese section repeats and reinforces export to external LLMs and robotic-arm kinematics engines, signaling cross-module integration beyond the narrow sensing purpose. In a robotics setting this matters because downstream consumers may treat the skill's outputs as action-ready, creating a pathway from environmental sensing to physical manipulation without clear controls or scope disclosure.

Static analysis

No suspicious patterns detected.