Back to skill

Security audit

Pilot Event Replay

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for event debugging, but its examples can capture broad sensitive event data insecurely and replay events with real downstream side effects.

Review before installing or using. Use this only with event streams you are authorized to capture, prefer a private directory and restrictive permissions for recordings, avoid broad wildcard captures unless necessary, redact sensitive data, and replay only into isolated test targets unless downstream systems are known to handle duplicates safely.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:64
Finding

Predictable and Potentially World-Readable Temporary Event Recording

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 64–68
Vulnerability Type: Unsafe temporary-file handling
Risk Level: Medium

bash
RECORDING="/tmp/debug-session-$(date +%Y%m%d-%H%M%S).ndjson"

pilotctl --json subscribe "$SOURCE" "*" --timeout "$DURATION" | \
  jq -c '.data.events[]' >> "$RECORDING"

Technical Analysis

The recording filename is generated predictably using a timestamp with one-second precision and placed directly in the shared /tmp directory. The shell's append redirection opens the path without atomically ensuring that it is a newly created regular file. If the path already exists as a symbolic link, the redirection follows that link.

The workflow also does not set a restrictive umask or explicitly restrict file permissions. Under a common 022 umask, a newly created recording can have mode 0644, allowing other local users to read it. Because the subscription uses the wildcard topic "*", the file may contain a broad range of sensitive operational event data.

Attack Path

  1. A local attacker determines when the recording workflow is likely to run.
  2. The attacker predicts the timestamp-derived pathname under /tmp.
  3. Before redirection occurs, the attacker creates that pathname as a symbolic link to a target file that the workflow's user can write.
  4. The user runs the documented workflow.
  5. The shell follows the symbolic link and appends captured events to the linked target.
  6. Independently, if a normal recording is created with a permissive default umask, another local user can open the resulting file and read captured events.

Exploitation requires local access and sufficient ability to create entries in the shared temporary directory. Symlink exploitation is further limited to destination files writable by the victim process; this workflow does not itself grant elevated privileges.

Impact Assessment

The primary impact is local confidentiality lo ...[truncated 533 chars]

Remediation
View remediation

Remediation Suggestions

Create the recording atomically with restrictive permissions rather than constructing a predictable pathname:

bash
umask 077
RECORDING=$(mktemp "${TMPDIR:-/tmp}/debug-session.XXXXXX.ndjson") || exit 1

pilotctl --json subscribe "$SOURCE" "*" --timeout "$DURATION" | \
  jq -c '.data.events[]' >> "$RECORDING"

For durable recordings, create and use a user-owned directory with mode 0700 outside shared /tmp, and create recording files with mode 0600. Validate that the destination is a regular file, avoid following symbolic links where platform APIs permit, apply an appropriate retention and secure-deletion policy, and warn users that wildcard subscriptions may capture sensitive data.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to record raw event streams to a local NDJSON file under /tmp without any warning about secrets, tokens, personal data, or other sensitive payloads that may appear in events. In this debugging and audit context, broad subscriptions and plaintext local storage materially increase the chance of unintended data exposure to other local users, backups, logs, or later mishandling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill provides a direct replay loop that republishes captured events to another target with no warning that replayed messages can retrigger workflows, duplicate state-changing operations, resend notifications, or cause other downstream side effects. Because the skill is specifically for debugging and testing event-driven systems, replay is expected, but the lack of guardrails, environment scoping, idempotency guidance, or safety warnings makes accidental harmful use more likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.