Back to skill

Security audit

Pilot Certificate

Security checks for vulnerabilities and agentic risk

Overview

The skill claims to issue and verify signed authorization certificates, but its documented commands create unsigned JSON files, grant admin capability by default, and treat simple timestamp checks as verification.

Review carefully before installing or using. Do not rely on this skill for real authorization unless it is changed to perform actual signing and signature verification, and avoid sending or accepting certificates that grant admin by default.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:40
Finding

Unsigned Capability Certificates Are Accepted as Verified

Content
View full analysis
~/.pilot/certificates/issued/cert-$CERT_ID.json <
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:47
Finding

Certificate Issuance Grants Administrator Capability by Default

Content
View full analysis
~/.pilot/certificates/issued/cert-$CERT_ID.json < ~/.pilot/certificates/issued/cert-$CERT_ID.json <
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill advertises Ed25519-signed capability certificates, but the implementation only writes unsigned JSON files and later treats them as certificates. Any attacker who can create or modify the JSON can grant themselves arbitrary capabilities such as admin, making the trust model fundamentally broken.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The examples explicitly claim cryptographic assurance but never perform signing or signature verification; they only parse JSON and compare timestamps. This can mislead users into deploying unauthenticated authorization artifacts, allowing forged certificates to be accepted as valid.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documentation includes commands that create certificate files under ~/.pilot/certificates and send them to a recipient with pilotctl, but the surrounding markdown does not warn users that it will write local files and transmit certificate data. For markdown files, user-facing warnings are expected when behavior can affect user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
#!/bin/bash
# Certificate authority

mkdir -p ~/.pilot/certificates/{issued,received}

CERT_ID=$(openssl rand -hex 8)
SUBJECT="admin.pilot"

Static analysis

No suspicious patterns detected.