Back to skill

Security audit

Pilot Auction

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent task-auction workflow, but it can automatically send task details to an unverified bidder selected from inbox messages.

Review this skill before installing if task specs may contain private, customer, proprietary, or credential-bearing information. Use it only with trusted or authenticated bidder identities, validate bid contents and ranges, require confirmation before awarding a task, and replace the predictable /tmp file pattern with a securely created private temporary directory.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:79
Finding

Unauthenticated Bidder Can Become the Task Recipient

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 79–91
Vulnerability Type: Missing bidder authentication and authorization
Risk Level: High

bash
while [ $(($(date +%s) - START_TIME)) -lt $AUCTION_DURATION ]; do
  pilotctl --json inbox | jq ".[] | select(.data.auction_id == \"$AUCTION_ID\")" >> "$BIDS_FILE"
  sleep 2
done

# Select winner by score
WINNER=$(jq -s 'map(. + {score: (1 - (.data.price / 100)) * 0.5 + .data.quality_guarantee * 0.5}) | sort_by(-.score) | .[0]' "$BIDS_FILE")

WINNER_ADDR=$(echo "$WINNER" | jq -r '.sender')
WINNER_PRICE=$(echo "$WINNER" | jq -r '.data.price')

# Award task
pilotctl --json task submit "$WINNER_ADDR" --task "video-transcoding: $TASK_SPEC"

Technical Analysis

The workflow accepts any inbox entry whose auction_id matches the current auction. It does not verify the sender's identity, message signature, eligibility, or authorization. It also does not validate the types and permitted ranges of price and quality_guarantee.

The sender address from the highest-scoring untrusted message is assigned directly to WINNER_ADDR. The workflow then sends $TASK_SPEC to that address without requester confirmation. Consequently, possession or prediction of the auction identifier is treated as sufficient authorization to participate and potentially receive the task.

Attack Path

  1. An attacker observes or predicts the timestamp-derived auction identifier.
  2. The attacker sends an inbox message containing that auction_id.
  3. The attacker supplies bid values designed to maximize the scoring expression, such as an abnormally low or negative price and a high quality guarantee.
  4. The collector accepts the message because it filters only by auction_id.
  5. The scoring operation ranks the malicious bid first.
  6. The attacker's sender address becomes WINNER_ADDR.
  7. pilotctl task submit transmits the task and $TASK_SPEC to the attacker-contro ...[truncated 650 chars]
Remediation
View remediation

Remediation Suggestions

  • Verify each bid's protocol-level digital signature and bind the verified identity to the sender address.
  • Limit participation to registered or explicitly approved bidder identities.
  • Use a cryptographically random, high-entropy auction nonce instead of relying solely on a timestamp-derived identifier.
  • Validate bids against a strict schema before scoring them. Require finite numeric values and enforce reasonable minimum and maximum ranges for price and quality.
  • Reject duplicate, expired, malformed, and replayed bids.
  • Confirm that the selected sender remains authorized immediately before submitting the task.
  • Require explicit requester approval before transmitting sensitive task specifications.
  • Minimize the information sent during task assignment and transfer sensitive data only over an authenticated, encrypted channel.
  • Handle the no-valid-bid case explicitly rather than allowing an empty or malformed winner value to reach pilotctl.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:74
Finding

Predictable Temporary File Allows Symlink-Based File Clobbering

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 74–75
Vulnerability Type: Unsafe temporary-file creation
Risk Level: Medium

bash
BIDS_FILE="/tmp/auction-bids-$AUCTION_ID.json"
echo "[]" > "$BIDS_FILE"

Technical Analysis

The workflow constructs a temporary-file path in the shared /tmp directory from AUCTION_ID, which is derived from the current Unix timestamp. Another local user can therefore predict likely filenames.

The shell redirection opens the path with truncation but does not create it atomically, reject symbolic links, verify ownership, or enforce restrictive permissions. If an attacker creates a symbolic link at the predicted path before the workflow reaches the redirection, the command follows that link and truncates its target. Later append operations can also write bid data to the linked target.

Attack Path

  1. A local attacker estimates the time at which the workflow will generate AUCTION_ID.
  2. The attacker creates one or more predicted paths such as /tmp/auction-bids-auction-EXPECTED_TIMESTAMP.json.
  3. Each predicted path is made a symbolic link to a file writable by the user running the auction.
  4. The workflow assigns the matching predictable path to BIDS_FILE.
  5. The echo "[]" > "$BIDS_FILE" redirection follows the symbolic link and truncates the target.
  6. Subsequent bid collection appends JSON data to that target.

Impact Assessment

A local attacker may cause the invoking account to truncate or modify another file that the account is permitted to write. If the skill runs under a privileged account, the affected scope expands to files writable by that account, potentially causing configuration corruption, denial of service, or security-relevant file modification.

Successful exploitation requires local access and accurate timing or pre-creation of candidate filenames. The snippet does not by itself allow modification of files outside the invoki ...[truncated 51 chars]

Remediation
View remediation

Remediation Suggestions

  • Create a private temporary directory atomically with mktemp -d.
  • Set umask 077 before creating files containing bids.
  • Store the bid file inside the private directory rather than directly under a predictable /tmp path.
  • Install an exit trap to remove the temporary directory on normal exit and interruption.
  • Fail immediately if secure temporary-file creation fails.
  • Avoid reopening attacker-influenceable paths; retain and use securely created files only.

Example hardened pattern:

bash
umask 077
BIDS_DIR=$(mktemp -d) || exit 1
trap 'rm -rf -- "$BIDS_DIR"' EXIT HUP INT TERM
BIDS_FILE="$BIDS_DIR/bids.json"
printf '%s\n' '[]' > "$BIDS_FILE"
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.