Back to skill

Security audit

Pilot Gossip

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed gossip-protocol helper, but its sample shell snippets need hardening before use in a real swarm.

Install only if you expect an agent to exchange state with pilotctl swarm peers. Treat the included snippets as illustrative, not production-ready: build JSON with jq or another encoder, validate message schemas and versions, authenticate peers, and define conflict-resolution rules before relying on it for important shared state.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

Unsafe JSON Construction Allows Gossip Message Manipulation

Content
View full analysis
Remediation
View remediation
&2 exit 1 ;; esac PAYLOAD=$( jq -cn \ --arg type "gossip_push" \ --argjson version "$STATE_VERSION" \ --argjson state "$STATE_DATA" \ --arg sender "$AGENT_ID" \ --argjson timestamp "$(date -u +%s)" \ '{ type: $type, version: $version, state: $state, sender: $sender, timestamp: $timestamp }' ) || exit 1 pilotctl --json send-message "$peer" --data "$PAYLOAD" ``` Additional hardening should include: 1. Validate state against an explicit JSON schema before transmission. 2. Require version and timestamp fields to be bounded non-negative integers. 3. Restrict agent identifiers to an approved format and length. 4. Set maximum payload sizes to prevent resource-exhaustion attacks. 5. Reject payload construction if `jq` fails rather than sending partial or malformed data. 6. Apply the same correction to both command examples in the file. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:49
Finding

Unvalidated Gossip Messages and Undefined Remote State Enable Incorrect State Merges

Content
View full analysis
Remediation
View remediation
= 0) and (.payload.state | type == "object") and (.payload.sender | type == "string") ' >/dev/null; then echo "Rejected invalid gossip message" >&2 continue fi REMOTE_VERSION=$(echo "$PAYLOAD" | jq -r '.payload.version') REMOTE_STATE=$(echo "$PAYLOAD" | jq -c '.payload.state') REMOTE_SENDER=$(echo "$PAYLOAD" | jq -r '.payload.sender') if [ "$REMOTE_VERSION" -gt "$MY_VERSION" ]; then MY_STATE=$( jq -cn \ --argjson local "$MY_STATE" \ --argjson remote "$REMOTE_STATE" \ '$local * $remote' ) || continue MY_VERSION=$REMOTE_VERSION fi ``` The implementation should also: 1. Authenticate peers and reject messages from senders outside the authorized swarm. 2. Protect message integrity with protocol-level signatures or authenticated transport. 3. Bind the authenticated peer identity to the declared `sender` field. 4. Validate state against a strict schema, including allowed keys, types, nesting depth, and size. 5. Reject negative, non-integer, excessively large, or replayed versions. 6. Update state and version atomically so failures cannot leave them inconsistent. 7. Define deterministic conflict-resolution and deletion semantics appropriate for eventual consistency, preferably using a suitable CRDT or version-vector design. 8. Log rejected messages without recording sensitive state contents. ]]>
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The merge example claims to apply newer remote state, but it never extracts REMOTE_STATE from the received message before merging. In practice this can cause incorrect or empty merges, state corruption, or silent failure of replication logic, which is especially risky in a gossip protocol where bad state can propagate across many peers.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.