Pilot Verify
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's instructions and required tooling align with its stated purpose (verifying Pilot Protocol agents), but there are small provenance and declaration gaps you should confirm before use.
This skill appears to do what it says: use pilotctl to look up agent identity, reputation (polo_score), and ping for reachability. Before installing/using it: 1) Confirm the pilotctl binary on PATH is the legitimate, up-to-date client from Pilot Protocol (verify checksum or vendor package) because the skill executes that binary locally. 2) Ensure jq and timeout are available on the system (SKILL.md uses them but they are not declared in metadata). 3) Be aware the skill assumes a running local pilot daemon — running a daemon exposes local agent state. 4) The skill source is listed as unknown in the registry metadata; if you need stronger assurance, verify the publisher (owner ID) and the project homepage (https://pilotprotocol.network) before trusting it. 5) If you run this in a high-sensitivity environment, consider executing the commands in a sandbox or reviewing pilotctl's behavior/logging to ensure no unexpected network or data exposure occurs.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
