Unfortunately, this is very easy. Not going to reveal how it's done, but it should be obvious. Why do you say we haven't seen this? Did you watch the vid in the OP where it was shown over and over?
Unfortunately, this is also very easy. Perhaps you should PM me because misinformation like this doesn't help.
The only part of the whole round-trip that's mildly complex is the undocking and traversing the mail slot. Since this was shown in the example vids, everyone should assume the remainder as a given.
What I saw in the vids was a very unsophisticated bot, obviously written by an amateur. As you say yourself, you or I could code one that would be virtually undetectable. So why is it so strange that given such an unsophisticated bot (and presumably operator), that it would accidentally be run in open, or through hubris (as has already been suggested by others), or it's simply bot timing error accidentally sending it into open.
This unsophisticated bot surfacing in open (accidentally or otherwise) is IMO the tip of the iceberg. You'd be naive not to assume that for every crude bot like this there might be dozens of other bots, far better coded, virtually undetectable, that always run in solo. For every hour this crude bot ran in open, we and FDev should assume thousands of hours running in solo, by this bot and many others.