Back to skill

Security audit

Pilot Compress

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward compression helper for Pilot Protocol transfers, but users should treat its send and receive examples as network-facing and handle files carefully.

Install only if you use Pilot Protocol and are comfortable with Bash examples that transmit data to named peers. Avoid sending secrets or personal data unless the recipient and transport are trusted, and decompress received content only after verifying the sender, using size limits, and working in a private directory.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:55
Finding

Unbounded Decompression of Untrusted Network Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 55-56 and 102-103
Vulnerability Type: Unrestricted decompression of remotely supplied data
Risk Level: Medium

Complete Code Snippet

Lines 55-56:

bash
COMPRESSED_DATA=$(echo "$INBOX" | jq -r '.items[0].content')
echo "$COMPRESSED_DATA" | base64 -d | gunzip

Lines 102-103:

bash
INBOX=$(pilotctl --json inbox)
echo "$INBOX" | jq -r '.items[0].content' | base64 -d | gunzip > report.json

Technical Analysis

The documented receiver workflow extracts the first inbox item's content and immediately passes it through Base64 decoding and gzip decompression. It does not authenticate or authorize the sender, verify the expected compression format, validate the encoded input, limit the compressed input size, restrict the decompressed output size, or impose CPU and execution-time limits.

Compression formats can encode extremely large outputs in relatively small payloads. A malicious peer could therefore submit a gzip bomb that consumes substantial CPU, memory, or disk space when the workflow is followed. The variant redirected to report.json is particularly exposed to filesystem exhaustion because decompressed data is written without an output-size limit.

Attack Path

  1. An attacker able to send a Pilot Protocol message to the recipient constructs a small gzip payload with a very high expansion ratio.
  2. The attacker Base64-encodes the payload and places it in the message content.
  3. The recipient runs the documented inbox workflow.
  4. jq selects the attacker's content without sender or message validation.
  5. base64 -d decodes the payload and gunzip expands it without resource limits.
  6. The process consumes excessive CPU, memory, or disk capacity, potentially disrupting the agent or host.

Impact Assessment

Successful exploitation does not directly grant additional system privileges. Its primary impact is denial ...[truncated 355 chars]

Remediation
View remediation

Remediation Suggestions

  • Authenticate the sender and verify that the selected inbox item comes from an authorized peer.
  • Validate message metadata, expected encoding, compression format, and compressed input size before processing.
  • Use strict Base64 decoding and stop processing when decoding or format validation fails.
  • Enforce a maximum decompressed size rather than piping unbounded output directly to a file.
  • Run decompression with operating-system resource limits for CPU time, memory, output file size, and execution duration.
  • Decompress into a private temporary directory on a filesystem with an appropriate quota.
  • Inspect gzip metadata where available, but do not rely on metadata alone because declared sizes can be absent or misleading.
  • Write to a temporary file, verify its final size and content type, and only then move it to the intended destination.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:73
Finding

Predictable Output Paths Allow Symbolic-Link File Clobbering

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 73, 85, and 103
Vulnerability Type: Unsafe temporary and output file handling
Risk Level: Medium

Complete Code Snippet

Predictable compressed output creation at line 73:

bash
gzip -c "$REPORT_FILE" > "$REPORT_FILE.gz"

Predictable file removal at line 85:

bash
rm "$REPORT_FILE.gz"

Predictable decompressed output creation at lines 102-103:

bash
INBOX=$(pilotctl --json inbox)
echo "$INBOX" | jq -r '.items[0].content' | base64 -d | gunzip > report.json

Technical Analysis

The workflow creates files under predictable names in the current working directory, including analytics-report.json.gz when the example value of REPORT_FILE is used and report.json for received content. Shell output redirection opens an existing destination with truncation and normally follows symbolic links.

If another user or process can modify the working directory, it can pre-create one of these paths as a symbolic link to another file writable by the workflow's user. When the command runs, redirection follows the link and truncates or replaces content in the target. The subsequent rm "$REPORT_FILE.gz" removes the link or generated path but does not restore data already overwritten through it.

Attack Path

  1. The attacker obtains write access to the directory in which the documented workflow will run.
  2. The attacker creates report.json or the expected $REPORT_FILE.gz path as a symbolic link to a file writable by the victim account.
  3. The victim runs the compression or receiver workflow.
  4. Shell redirection follows the symbolic link and opens the target with truncation.
  5. Compressed or decompressed data is written over the target, or the target is left empty if processing fails after it is opened.
  6. The attacker causes data loss or configuration corruption within the victim user's existing write permissions.

...[truncated 507 chars]

Remediation
View remediation

Remediation Suggestions

  • Create intermediate files in a private directory owned by the executing user and inaccessible to untrusted users.
  • Use mktemp to generate unpredictable temporary file paths.
  • Set umask 077 before creating files containing received or locally sourced data.
  • Refuse to overwrite existing destinations and explicitly reject symbolic links.
  • Where supported, open files with no-follow and exclusive-creation semantics.
  • Validate the completed temporary output before atomically moving it to the final destination.
  • Add cleanup traps that remove only temporary files created by the current process.
  • Avoid running the workflow from shared or attacker-writable directories.
  • Require explicit confirmation or a safe overwrite policy when the final destination already exists.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly instructs users to send compressed messages and files to remote hosts via pilotctl send-message and send-file, but it does not warn that data is leaving the local system or discuss trust boundaries, sensitivity of payloads, or whether transport security is in place. In an agent skill context, omission of outbound-data warnings can lead to inadvertent exfiltration of sensitive files or message contents, especially because compression and base64 encoding may make the transfer look innocuous rather than clearly network-facing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.