Pilot Archive
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's instructions, required binaries, and file reads/writes are consistent with an archive/search utility for Pilot Protocol; there are minor manifest omissions (jq/tar) but no apparent misdirection or extraneous credential requests.
This skill appears to do what it says: locally index and search Pilot Protocol history. Before installing: (1) ensure pilotctl and jq are installed and the pilot daemon is trusted/running locally; the SKILL.md expects jq and mentions tar/gzip but the registry metadata doesn't list jq — consider adding it to required binaries. (2) Be aware it will copy message and file metadata/content into $HOME/.pilot/archive (sensitive data stored locally). (3) Review/limit file permissions on the archive directory and vet pilotctl (it can access your messages). (4) Test commands manually to confirm no unexpected network activity. If you need stronger privacy controls, avoid indexing or add filters to exclude sensitive messages.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
