Pilot Formation
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's requirements and instructions are coherent for forming network topologies with pilotctl, but review and test it before use because it performs privileged network actions (handshakes/approvals/publish) and the SKILL.md omits declaring jq as a required binary.
This skill is coherent for forming swarms using the pilotctl tool, but you should only install it if you trust the pilotctl binary and the pilot daemon on your host. Before installing: (1) verify pilotctl and jq are installed from trusted sources (SKILL.md uses jq but the registry metadata does not list it), (2) review the handshake/approve loops — they will automatically approve pending nodes which could add untrusted peers to your topology, (3) confirm where pilotctl will publish topology data (REGISTRY_HOST) so you don't inadvertently leak sensitive metadata, (4) test in an isolated environment first, and (5) ensure you have logging/backup of current topology in case you need to roll back. If you need lower risk, request a version that requires manual approval steps instead of bulk/automated approvals.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
