Back to skill

Security audit

Unitree Hermes Colab

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with read-only Colab robotics review, but its automatic activation and incomplete safety checker make it risky enough to require review before installation.

Install only if you want a read-only Unitree/Hermes Colab review helper and can enforce the no-live-robot boundary yourself. Treat its validation script as advisory, not proof of safety, and manually review generated reports/runbooks before following any robotics or network instructions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check_lab_artifacts.py:20
Finding

Safety Validator Can Approve Artifacts Containing Dangerous Robot or Network Commands

Content
View full analysis

Vulnerability Details

File Location: scripts/check_lab_artifacts.py:20-25, 52-54
Vulnerability Type: Incomplete validation and insufficient dangerous-command detection
Risk Level: Medium

Vulnerable Code:

python
DANGEROUS_PATTERNS = (
    re.compile(r"\bssh\b.*\b192\.168\.123\.", re.IGNORECASE),
    re.compile(r"\bscp\b.*\b192\.168\.123\.", re.IGNORECASE),
    re.compile(r"\bdds\b.*\b(pub|publish|write|send)\b", re.IGNORECASE),
    re.compile(r"\bros2\s+topic\s+pub\b", re.IGNORECASE),
)
python
prompts = "\n".join(use_case.get("prompt", "") for use_case in payload.get("use_cases", []))
if any(pattern.search(prompts) for pattern in DANGEROUS_PATTERNS):
    print("dangerous robot/network command pattern found in prompts", file=sys.stderr)
    return 1

Technical Analysis

The validator searches only the prompt property of each object under use_cases. It does not inspect other potentially executable or user-facing content, such as runbooks, reports, flow data, gate details, or additional JSON properties. Consequently, prohibited robot-control or robot-network commands can be placed outside the narrowly inspected fields without detection.

The denylist is also incomplete relative to the safety boundaries in SKILL.md. It recognizes only selected SSH/SCP commands targeting addresses beginning with 192.168.123., selected DDS wording, and ros2 topic pub. It does not generally detect alternate robot addresses, ROS service or action calls, Unitree SDK actuation APIs, command aliases, shell indirection, or multiline variants.

In addition, required gate statuses are accepted as assertions supplied by the artifact rather than derived from independently validated evidence. An artifact can therefore claim that safety gates passed even when uninspected content contradicts those claims.

Attack Path

  1. Create a review JSON artifact containing every required gate name.
  2. Mar ...[truncated 1282 chars]
Remediation
View remediation

Remediation Suggestions

  1. Define and enforce a strict JSON schema, including expected types for gates, use cases, reports, runbooks, flow data, and other artifact fields.
  2. Recursively inspect every user-facing or potentially executable text field rather than only use_cases[*].prompt.
  3. Reject unknown fields that could conceal executable instructions, or explicitly classify each field as safe metadata versus content requiring safety validation.
  4. Prefer allowlisted, structured representations of permitted operations over a regex-only denylist.
  5. Expand detection to cover ROS topics, services, and actions; DDS publication variants; Unitree SDK motor and sport-mode APIs; remote-access commands; alternate robot subnets; multiline commands; shell indirection; aliases; and encoded command forms.
  6. Derive required safety-gate results from validator evidence instead of trusting artifact-supplied status values.
  7. Add negative tests containing dangerous commands in every supported text field and using syntax variants not covered by the current patterns.
  8. Keep the checker advisory unless enforcement can guarantee complete semantic analysis, and clearly document residual limitations to prevent users from treating a passing result as proof of operational safety.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill enables allow_implicit_invocation without any narrowly scoped activation guard, which can cause the skill to be triggered in broader contexts than intended. Because this skill concerns Google Colab workflows, Hermes Agent usage, and robotics-related analysis, unintended activation could expose users to unsafe or out-of-scope guidance, including actions adjacent to robotics operations, even if the description says not to use it for live robot control.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.