Back to skill

Security audit

Pilot Github Bridge

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent with its GitHub-to-Pilot bridge purpose, but its example exposes a public event relay and uses webhook data to trigger downstream agents without documenting basic authentication or validation controls.

Review this skill carefully before installing. Use it only with a private or authenticated relay, GitHub webhook signature verification, repository and branch allowlists, strict event validation, replay/rate limiting, and least-privilege downstream agents. Do not run the public relay example as-is for production automation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:62
Finding

Untrusted Webhook Data Is Embedded into Downstream Control Messages

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:53
Finding

Public Daemon and Relay Exposure Lacks Documented Access Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs users to run a public daemon and an externally exposed webhook relay, then consume and act on inbound GitHub event data without documenting authentication, signature verification, sender validation, or replay protection. In this context, untrusted network input is directly used to trigger downstream agent actions such as builds and code review messages, which can let an attacker spoof events or induce unauthorized workflow execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest explicitly scopes the skill to bridging webhook events and says not to use it for direct GitHub API access. However, the dependency list states that gh CLI is required, which implies GitHub API tooling outside the webhook-bridge purpose and does not match the rest of the documented workflow, which never uses gh.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.