Back to skill

Security audit

Pilot Announce Capabilities

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward guide for publishing capability information to a Pilot Protocol network, with some disclosure-risk caveats users should review.

Before using this skill, review any capability manifest carefully and remove infrastructure details you do not want visible to other Pilot Protocol peers or registries, such as hostnames, node IDs, endpoints, region, GPU inventory, pricing, or SLA commitments. Treat registry targets as external recipients.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-level guidance explicitly directs users away from this skill when they need discovery. Later sections contradict that intent by documenting subscribe, peers --search, and a workflow using find registry, all of which are discovery-related operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs users to publish structured capability manifests to a network without warning that fields like hostname, node ID, endpoints, location, GPU inventory, pricing, and SLA data may be sensitive. This can cause unintentional information disclosure that aids fingerprinting, targeting, or competitive intelligence collection by untrusted parties on the network.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest frames this skill as an announcement/publishing capability and explicitly says not to use it to discover other agents. However, the documented operations include subscribing to announcements and listing peer capabilities, which are discovery-oriented behaviors rather than merely broadcasting one's own capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow example actively discovers a registry and publishes manifest contents to it without any user-facing warning or confirmation that data is leaving the local environment. In practice, this increases the risk of accidental exfiltration of operational metadata and service details to an external party or broadly visible registry.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.