Pilot Workflow
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's requirements and runtime instructions are coherent with a Pilot Protocol workflow orchestrator; nothing requested or instructed is unrelated to that purpose.
This skill appears to be what it claims: a YAML-driven orchestrator that uses pilotctl to dispatch tasks to agents. Before installing or using it: 1) Ensure pilotctl points to a trusted Pilot Protocol daemon and that you trust peers selected by tag, because tasks (including their payloads) will be sent to remote agents. 2) Do not include secrets or sensitive data in step.task fields. 3) Install and verify jq and yq (the SKILL.md requires them, but the registry metadata only declared pilotctl — ensure those binaries are available). 4) Note the AGPL-3.0 license if that affects your project. If you want tighter safety, add validation or sanitization of task payloads and restrict which agent tags can be targeted.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
