Back to skill

Security audit

Pilot Backup

Security checks for vulnerabilities and agentic risk

Overview

This backup skill is purpose-aligned but handles sensitive agent state and restores remote archives in ways users should review carefully before installing.

Install only if you trust the pilotctl transport and the configured peers, and review the exact files under $HOME/.pilot before backup. Do not use the restore command as written with untrusted or unauthenticated peers; a safer workflow would verify sender identity, signatures or hashes, inspect archive paths, extract into a temporary directory, and require explicit approval before replacing live state.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:37
Finding

Sensitive agent state is archived and transmitted without demonstrated encryption or peer verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 37-42
Vulnerability Type: Plaintext handling and transmission of sensitive backup data
Risk Level: High

Vulnerable Code:

bash
BACKUP_DEST="1:0001.AAAA.BBBB"
BACKUP_FILE="/tmp/pilot-backup-$(date +%Y%m%d_%H%M%S).tar.gz"

tar czf "$BACKUP_FILE" "$HOME/.pilot"/*.json
pilotctl --json send-file "$BACKUP_DEST" "$BACKUP_FILE"
rm "$BACKUP_FILE"

Technical Analysis

The documented workflow packages every JSON file under $HOME/.pilot into an ordinary gzip-compressed tar archive. Compression does not provide encryption. The archive is then sent to a hardcoded peer identifier without any documented verification of the peer's identity, cryptographic fingerprint, or authorization to receive the selected files.

The skill description claims encrypted backup storage on trusted peers, but the shown commands do not perform client-side encryption or demonstrate that pilotctl provides authenticated end-to-end encryption. Because the external pilotctl implementation is not included in the audited project, any encryption or authentication it may provide could not be verified.

The broad *.json selection can include credentials, access tokens, private configuration, peer metadata, or other sensitive agent state. The temporary archive is also created without setting a restrictive umask or explicitly assigning permissions, potentially making it readable by other local users depending on the environment's defaults.

Attack Path

  1. A user or automated agent invokes the documented backup workflow.
  2. All matching $HOME/.pilot/*.json files are placed into an unencrypted gzip archive.
  3. The archive is written to the shared /tmp hierarchy without an explicitly restrictive permission policy.
  4. The workflow sends the archive to the configured destination without verifying the destination's authenticated identity or expected cryptographic fingerprint ...[truncated 1051 chars]
Remediation
View remediation

Remediation Suggestions

  • Encrypt the archive locally before transmission using authenticated encryption and a verified recipient public key.
  • Verify the destination peer against an explicit allowlist and pinned cryptographic fingerprint rather than relying only on a peer identifier.
  • Document and enforce the authentication and end-to-end encryption guarantees supplied by pilotctl.
  • Replace the broad *.json wildcard with an explicit allowlist of files required for restoration.
  • Exclude secrets that can be regenerated or obtained from a dedicated secret-management system.
  • Set umask 077 before archive creation and explicitly apply mode 0600 to temporary and retained backup files.
  • Use a private temporary directory created with mktemp -d instead of a predictable filename directly under /tmp.
  • Add cryptographic signatures or authenticated manifests so recipients can verify archive origin and integrity.
  • Ensure cleanup occurs through a shell trap even if archive creation or transmission fails.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:45
Finding

Unvalidated remote archive is extracted directly into live agent state

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 45-50
Vulnerability Type: Untrusted archive extraction and insufficient response authentication
Risk Level: High

Vulnerable Code:

bash
pilotctl --json send-message "$BACKUP_PEER" --data '{"type":"backup_request","date":"latest"}'
sleep 3

BACKUP_FILE=$(pilotctl --json received | jq -r '.received[0].filename')
tar xzf "$HOME/.pilot/received/$BACKUP_FILE" -C "$HOME/.pilot/"

Technical Analysis

The restore workflow selects the first item returned by pilotctl --json received after an arbitrary three-second delay. It does not verify that the item was sent by $BACKUP_PEER, corresponds to the current request, is an expected backup, or carries a valid cryptographic signature or integrity value.

The remote filename is interpolated into a local path without validating its format. More importantly, the selected archive is extracted directly into the live $HOME/.pilot directory without first inspecting its members. The workflow does not reject absolute paths, parent-directory traversal components, symbolic links, hard links, device entries, or unexpected files.

Even where the installed tar implementation blocks some traversal patterns, relying on implementation-specific extraction behavior is insufficient. A malicious archive may overwrite legitimate state files, introduce unsafe links, or add attacker-controlled files that other agent components later trust or process.

Attack Path

  1. The victim sends a backup request to the expected peer.
  2. An attacker, compromised peer, or unrelated sender places a crafted archive in the victim's received-file queue before the expected response is selected.
  3. After the fixed delay, the workflow selects .received[0].filename without checking sender identity, request correlation, content type, filename format, signature, or digest.
  4. The crafted archive contains replacement configuration or state ...[truncated 1311 chars]
Remediation
View remediation

Remediation Suggestions

  • Correlate each received backup with a unique request identifier and require the response to come from the authenticated expected peer.
  • Verify a digital signature and authenticated manifest before processing any archive.
  • Require an expected cryptographic digest obtained through a trusted channel.
  • Validate the received filename against a strict allowlist pattern and resolve the final path before use.
  • Enumerate archive members before extraction and reject absolute paths, .. components, symbolic links, hard links, device files, sockets, and all unexpected filenames.
  • Extract into a newly created private temporary directory rather than directly into $HOME/.pilot.
  • Restore only explicitly allowlisted files after validating their type, ownership, size, permissions, and schema.
  • Preserve the current state and perform the final replacement atomically so a failed validation or extraction cannot corrupt the live installation.
  • Replace the fixed sleep and first-item selection with a protocol-level wait for the specific authenticated response.
  • Run restoration with the minimum necessary operating-system privileges and never as a privileged account.
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

BACKUP_STORAGE="$HOME/.pilot/backup-storage" MAX_BACKUPS=7

ls -1t "$BACKUP_STORAGE"/pilot-backup-*.tar.gz | tail -n +$((MAX_BACKUPS + 1)) | xargs rm -f

text

## Workflow Example

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

BACKUP_STORAGE="$HOME/.pilot/backup-storage" MAX_BACKUPS=7

ls -1t "$BACKUP_STORAGE"/pilot-backup-*.tar.gz | tail -n +$((MAX_BACKUPS + 1)) | xargs rm -f

text

## Workflow Example

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The restore flow untars a file received from a remote peer directly into the agent state directory without validating the archive contents, authenticity, or whether files will be overwritten. A malicious or compromised peer could supply a tarball containing path traversal entries, symlinks, or crafted state files that overwrite configuration and potentially alter agent behavior or persistence.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.