Pilot Workflow

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's requirements and runtime instructions are coherent with a Pilot Protocol workflow orchestrator; nothing requested or instructed is unrelated to that purpose.

This skill appears to be what it claims: a YAML-driven orchestrator that uses pilotctl to dispatch tasks to agents. Before installing or using it: 1) Ensure pilotctl points to a trusted Pilot Protocol daemon and that you trust peers selected by tag, because tasks (including their payloads) will be sent to remote agents. 2) Do not include secrets or sensitive data in step.task fields. 3) Install and verify jq and yq (the SKILL.md requires them, but the registry metadata only declared pilotctl — ensure those binaries are available). 4) Note the AGPL-3.0 license if that affects your project. If you want tighter safety, add validation or sanitization of task payloads and restrict which agent tags can be targeted.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal