Back to skill

Security audit

Pilot Blocklist

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for managing Pilot Protocol blocklists, but it includes persistent trust-revocation commands and an automatic peer-blocking workflow without enough confirmation or safety scoping.

Review this skill carefully before installing. Use it only if you are comfortable with commands that can persistently block Pilot Protocol peers and revoke trust, and prefer adding manual confirmation, backups, safer temp-file handling, and exact hostname matching before running the automatic workflow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:61
Finding

Predictable Shared Temporary File Enables Blocklist Tampering and File Races

Content
View full analysis
/tmp/blocklist.json && mv /tmp/blocklist.json ~/.pilot/blocklists/default.json ``` ```bash jq --arg agent "$AGENT" '.entries = [.entries[] | select(.hostname != $agent)]' \ ~/.pilot/blocklists/default.json > /tmp/blocklist.json && mv /tmp/blocklist.json ~/.pilot/blocklists/default.json ``` ```bash jq --arg agent "$AGENT" --arg node "$NODE_ID" --arg reason "$REASON" \ '.entries += [{hostname: $agent, node_id: $node, reason: $reason, blocked_at: (now | strftime("%Y-%m-%dT%H:%M:%SZ"))}] | .entries |= unique_by(.hostname)' \ "$BLOCKLIST" > /tmp/blocklist.json && mv /tmp/blocklist.json "$BLOCKLIST" ``` ### Technical Analysis Every blocklist update uses the same globally predictable path, `/tmp/blocklist.json`. The command does not create the file exclusively, verify its ownership or type, restrict its permissions, or isolate concurrent operations. A local process able to manipulate the temporary path may race the update or pre-create the path. Depending on operating-system protections and the relationship between the attacking and executing accounts, symbolic-link attacks may cause shell redirection to follow an unintended target. Even where protected-symlink and sticky-directory controls prevent cross-user exploitation, concurrent skill invocations under the same account can overwrite each other's temporary data or move stale content into the persistent blocklist. Because the temporary file is moved into a security-sensitive configuration path, interference can affect both the integrity and availability of d ...[truncated 1421 chars]
Remediation
View remediation
"$tmp" && jq -e . "$tmp" >/dev/null && mv -- "$tmp" "$BLOCKLIST"; then trap - EXIT HUP INT TERM else exit 1 fi ``` Additional hardening measures: - Keep the temporary file in the same directory as the destination so the final rename is atomic and does not cross filesystems. - Ensure `~/.pilot/blocklists` is owned by the expected account and is not writable by other users. - Set an appropriate restrictive `umask`, such as `umask 077`. - Use a lock, such as `flock`, if concurrent blocklist updates are possible. - Validate the generated JSON before replacing the active blocklist. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:77
Finding

Attacker-Controlled Hostname Is Interpreted as a Regular Expression

Content
View full analysis
Remediation
View remediation
/dev/null; then NODE_ID=$(pilotctl --json pending | jq -r --arg h "$HOSTNAME" '.[] | select(.hostname == $h) | .node_id') pilotctl --json reject "$NODE_ID" "Blocklisted" fi ``` Additionally: - Validate hostnames against the exact naming rules enforced by Pilot Protocol. - Reject malformed or empty identifiers before making trust decisions. - Capture the pending-peer response once per enforcement pass to avoid inconsistent results between repeated `pilotctl pending` calls. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

Commands

Create blocklist:

bash
mkdir -p ~/.pilot/blocklists
cat > ~/.pilot/blocklists/default.json <<EOF

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

These instructions directly revoke trust, reject a node, and persistently modify a blocklist without any explicit warning that the actions are state-changing and may disrupt legitimate connectivity. In an agent skill context, users may paste or automate these commands without appreciating that they can permanently deny service to the wrong peer if hostname resolution or selection is incorrect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The automatic workflow silently rejects agents and updates a persistent deny-list based on a score threshold, with no warning about operational impact or false-positive risk. In a trust-management skill, unattended enforcement can amplify bad inputs or transient scoring issues into long-lived blocking decisions that interrupt legitimate network relationships.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest frames this skill as maintaining and sharing blocklists of already identified untrusted agents. The example code goes further by automatically evaluating all peers on a polo_score threshold and blocking them, which introduces reputation-based policy enforcement not described in the skill's stated purpose or usage guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.