Pilot Legal Contract Review Setup
Security checks across malware telemetry and agentic risk
Overview
The skill's instructions, required binaries, and file writes are consistent with setting up a three-agent contract-review pipeline; nothing requested is disproportionate to that purpose, though you should still vet the pilotctl/clawhub binaries and any installed pilot-* skills before use.
This skill appears coherent for deploying a three-agent contract-review pipeline, but take these precautions before installing: - Verify the authenticity and integrity of the pilotctl and clawhub binaries (they drive all actions here). If possible, install from official sources and check signatures. - Inspect the pilot-* skills you will install with clawhub (pilot-webhook-bridge, pilot-share, etc.) — they may request network access, webhook URLs, or secrets that could transmit sensitive contract data. - Note that the system's handshake flow auto-approves trust when both sides exchange handshakes; only perform handshakes between hosts you control/trust. - Confirm what webhook endpoints the summarizer will send data to and ensure any external integrations are authorized and encrypted (HTTPS). Avoid sending raw contract text to untrusted endpoints. - Back up or review the manifest written to ~/.pilot/setups/legal-contract-review.json and set appropriate filesystem permissions if you handle sensitive legal documents.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
66/66 vendors flagged this skill as clean.
