Pilot Multi Region Content Sync Setup

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent setup guide for Pilot multi-region content sync, with disclosed local configuration and network trust steps.

Install this only if you intend to configure Pilot agents for cross-host content replication. Confirm the role, prefix, peer hostnames, and ~/.pilot manifest path before running setup, and only handshake with hosts you control or trust. Review the named pilot-* skills and ensure pilotctl and clawhub come from trusted sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to write a persistent manifest under ~/.pilot and to facilitate cross-host content transfer and handshakes, but it does not require any user confirmation or warning before making these stateful and network-relevant changes. In an agent setting, silently persisting configuration and enabling future transmission paths can lead to unintended data replication, misconfiguration, or unauthorized operational changes on the host.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal