T09 · Insecure Skill Coding Practices
- Location
SKILL.md:37- Finding
Sensitive agent state is archived and transmitted without demonstrated encryption or peer verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 37-42
Vulnerability Type: Plaintext handling and transmission of sensitive backup data
Risk Level: HighVulnerable Code:
bash BACKUP_DEST="1:0001.AAAA.BBBB" BACKUP_FILE="/tmp/pilot-backup-$(date +%Y%m%d_%H%M%S).tar.gz" tar czf "$BACKUP_FILE" "$HOME/.pilot"/*.json pilotctl --json send-file "$BACKUP_DEST" "$BACKUP_FILE" rm "$BACKUP_FILE"Technical Analysis
The documented workflow packages every JSON file under
$HOME/.pilotinto an ordinary gzip-compressed tar archive. Compression does not provide encryption. The archive is then sent to a hardcoded peer identifier without any documented verification of the peer's identity, cryptographic fingerprint, or authorization to receive the selected files.The skill description claims encrypted backup storage on trusted peers, but the shown commands do not perform client-side encryption or demonstrate that
pilotctlprovides authenticated end-to-end encryption. Because the externalpilotctlimplementation is not included in the audited project, any encryption or authentication it may provide could not be verified.The broad
*.jsonselection can include credentials, access tokens, private configuration, peer metadata, or other sensitive agent state. The temporary archive is also created without setting a restrictiveumaskor explicitly assigning permissions, potentially making it readable by other local users depending on the environment's defaults.Attack Path
- A user or automated agent invokes the documented backup workflow.
- All matching
$HOME/.pilot/*.jsonfiles are placed into an unencrypted gzip archive. - The archive is written to the shared
/tmphierarchy without an explicitly restrictive permission policy. - The workflow sends the archive to the configured destination without verifying the destination's authenticated identity or expected cryptographic fingerprint ...[truncated 1051 chars]
- Remediation
View remediation
Remediation Suggestions
- Encrypt the archive locally before transmission using authenticated encryption and a verified recipient public key.
- Verify the destination peer against an explicit allowlist and pinned cryptographic fingerprint rather than relying only on a peer identifier.
- Document and enforce the authentication and end-to-end encryption guarantees supplied by
pilotctl. - Replace the broad
*.jsonwildcard with an explicit allowlist of files required for restoration. - Exclude secrets that can be regenerated or obtained from a dedicated secret-management system.
- Set
umask 077before archive creation and explicitly apply mode0600to temporary and retained backup files. - Use a private temporary directory created with
mktemp -dinstead of a predictable filename directly under/tmp. - Add cryptographic signatures or authenticated manifests so recipients can verify archive origin and integrity.
- Ensure cleanup occurs through a shell trap even if archive creation or transmission fails.
