T09 · Insecure Skill Coding Practices
- Location
SKILL.md:40- Finding
Unsigned Capability Certificates Are Accepted as Verified
- Content
View full analysis
~/.pilot/certificates/issued/cert-$CERT_ID.json <- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill claims to issue and verify signed authorization certificates, but its documented commands create unsigned JSON files, grant admin capability by default, and treat simple timestamp checks as verification.
Review carefully before installing or using. Do not rely on this skill for real authorization unless it is changed to perform actual signing and signature verification, and avoid sending or accepting certificates that grant admin by default.
SKILL.md:40Unsigned Capability Certificates Are Accepted as Verified
SKILL.md:47Certificate Issuance Grants Administrator Capability by Default
The skill advertises Ed25519-signed capability certificates, but the implementation only writes unsigned JSON files and later treats them as certificates. Any attacker who can create or modify the JSON can grant themselves arbitrary capabilities such as admin, making the trust model fundamentally broken.
The examples explicitly claim cryptographic assurance but never perform signing or signature verification; they only parse JSON and compare timestamps. This can mislead users into deploying unauthenticated authorization artifacts, allowing forged certificates to be accepted as valid.
The skill documentation includes commands that create certificate files under ~/.pilot/certificates and send them to a recipient with pilotctl, but the surrounding markdown does not warn users that it will write local files and transmit certificate data. For markdown files, user-facing warnings are expected when behavior can affect user data, privacy, or system integrity.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
#!/bin/bash
# Certificate authority
mkdir -p ~/.pilot/certificates/{issued,received}
CERT_ID=$(openssl rand -hex 8)
SUBJECT="admin.pilot"
No suspicious patterns detected.