Pilot Inbox
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's requests and runtime instructions are consistent with a read/triage-only inbox tool for the Pilot Protocol, with only a small documentation omission (jq is used but not listed as a required binary).
This skill appears coherent for viewing and triaging Pilot Protocol inbox items, but check a few things before installing: (1) Ensure pilotctl is a trusted binary and up-to-date (verify its source and checksum); (2) Install or confirm jq on PATH (SKILL.md uses it but the registry metadata doesn't list it); (3) Be aware that pilotctl --clear is destructive — the agent running this skill could delete items if asked to; (4) Confirm the Pilot Protocol daemon is running and that you intend to grant that local access to the agent; (5) If you need the skill to run automatically, remember autonomous invocation is allowed by default — restrict if you don't want the agent to execute these commands without your approval.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
