Back to skill

Security audit

Pilot Audit Log

Security checks for vulnerabilities and agentic risk

Overview

This skill gives visible, purpose-aligned audit-log commands, but users should treat the generated local logs as sensitive and not forensic-grade by default.

Install only if you intend to keep local Pilot trust and connection audit records. Before using it for compliance or incident response, set restrictive permissions on ~/.pilot/audit, decide how long to retain logs, avoid storing unnecessary agent details, and prefer JSON-safe logging such as jq-based encoding for records influenced by external agent names or inputs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:56
Finding

Audit Log Injection Through Unescaped Event Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56–61 and 89–96
Vulnerability Type: Audit-log injection and malformed JSON generation
Risk Level: Medium

Vulnerable Code

Lines 56–61:

bash
log_audit() {
  local EVENT_TYPE=$1
  local DETAILS=$2
  echo "$(date -u +%Y-%m-%dT%H:%M:%SZ) $EVENT_TYPE $DETAILS" >> ~/.pilot/audit/events.jsonl
}

Lines 89–96:

bash
audit_log() {
  local EVENT_TYPE=$1
  local AGENT=$2
  local ACTION=$3
  local RESULT=$4

  cat >> "$LOG_FILE" <<EOF
{"timestamp":"$(date -u +%Y-%m-%dT%H:%M:%SZ)","event_type":"$EVENT_TYPE","agent":"$AGENT","action":"$ACTION","result":"$RESULT"}
EOF
}

Technical Analysis

Both logging implementations interpolate input directly into audit records without applying JSON encoding or rejecting newline and control characters.

The first implementation writes an unstructured, space-delimited record to a file named events.jsonl. This conflicts with subsequent examples that process the same file as JSON. A value containing a newline can create additional attacker-controlled log lines.

The second implementation places variables directly inside JSON string literals. An agent identifier or other value containing quotation marks, backslashes, newlines, or JSON syntax can terminate the intended field, corrupt the record, or inject additional fields and forged records. Shell variable expansion does not recursively execute shell syntax contained in these values, so the demonstrated issue is log and JSON injection rather than shell command execution.

Attack Path

  1. An attacker supplies or influences an agent identifier, event detail, action, or result processed by the wrapper.
  2. The attacker includes quotation marks, JSON delimiters, or newline characters in that value.
  3. The logging function interpolates the value directly into events.jsonl.
  4. The crafted value creates malformed JSON or ...[truncated 727 chars]
Remediation
View remediation

Remediation Suggestions

  • Generate every JSONL record with a JSON-aware encoder instead of string interpolation. For example:

    bash
    jq -cn \
      --arg timestamp "$(date -u +%Y-%m-%dT%H:%M:%SZ)" \
      --arg event_type "$EVENT_TYPE" \
      --arg agent "$AGENT" \
      --arg action "$ACTION" \
      --arg result "$RESULT" \
      '{timestamp:$timestamp,event_type:$event_type,agent:$agent,action:$action,result:$result}' \
      >> "$LOG_FILE"
    
  • Use one consistent JSONL schema throughout initialization, logging, querying, and reporting.

  • Validate identifiers and event types against explicit allowlists where practical.

  • Reject unexpected control characters when multiline values are not required.

  • Quote all filesystem paths and initialize the audit directory with restrictive permissions, such as umask 077 and directory mode 0700.

  • Validate generated records with jq -e before committing them to the authoritative audit log.

  • Consider append-only or integrity-protected storage if the audit trail is intended to provide compliance or forensic evidence.

Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the user to create persistent audit logs under ~/.pilot/audit and append trust activity to a file in the home directory, but it does not warn that these logs may contain sensitive metadata about agents, trust decisions, and operational activity. In a security/compliance context, silent long-term local retention increases the risk of privacy leakage, unauthorized local access, and accidental disclosure during backups or incident response sharing.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill establishes session-like persistence by creating a durable audit directory and configuration with a 90-day retention period in the user's home directory. While this appears intended for legitimate auditing, it still creates a persistent record of security-relevant actions that may outlive the immediate task and expose historical activity to other local users, malware, or backup systems if not properly protected.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

Initialize audit log:

bash
mkdir -p ~/.pilot/audit
cat > ~/.pilot/audit/config.json <<EOF
{
  "enabled": true,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow example both initiates Pilot handshakes and records compliance/audit data, but it provides no user-facing notice about the privacy implications of creating connection records and retaining them for later review. Because the skill is specifically for audit and incident investigation, the collected logs are more likely to contain sensitive operational context, making omission of retention and disclosure guidance materially risky.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.