Back to skill

Security audit

Pilot Broadcast

Security checks for vulnerabilities and agentic risk

Overview

The skill is a small broadcast helper, but its documentation is unclear about who receives messages and could cause users to send operational updates to the wrong scope.

Install only if you understand the Pilot Protocol delivery model and verify whether publish sends to one peer, a broker, or all trusted peers. Do not include credentials, tokens, private keys, personal data, or sensitive operational details in messages until the recipient scope is explicit.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill encourages sending announcements, status updates, and network-wide notifications over a trusted-peer network without warning that message contents may be visible to multiple remote agents and should be treated as shared data. This increases the risk of operators broadcasting secrets, internal state, or sensitive operational details under the false assumption that 'trusted peers' implies low disclosure risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises one-to-many broadcast semantics, but the documented publish command targets a specific hostname, which can mislead an agent into believing a message will reach all trusted peers when it only reaches one peer. In security-sensitive workflows, this mismatch can cause failed alerts, incomplete coordination, or accidental disclosure to the wrong recipient because operators may select commands based on incorrect mental models.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow example reinforces the misleading claim of broadcasting to trusted peers while actually sending to a single named agent. Examples are often copied verbatim, so this inconsistency can propagate incorrect use in production and lead to missed notifications or communication with an unintended single endpoint instead of the expected trust network.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.