Back to skill

Security audit

Pilot Legal Contract Review Setup

Security checks across malware telemetry and agentic risk

Overview

The skill's instructions, required binaries, and file writes are consistent with setting up a three-agent contract-review pipeline; nothing requested is disproportionate to that purpose, though you should still vet the pilotctl/clawhub binaries and any installed pilot-* skills before use.

This skill appears coherent for deploying a three-agent contract-review pipeline, but take these precautions before installing: - Verify the authenticity and integrity of the pilotctl and clawhub binaries (they drive all actions here). If possible, install from official sources and check signatures. - Inspect the pilot-* skills you will install with clawhub (pilot-webhook-bridge, pilot-share, etc.) — they may request network access, webhook URLs, or secrets that could transmit sensitive contract data. - Note that the system's handshake flow auto-approves trust when both sides exchange handshakes; only perform handshakes between hosts you control/trust. - Confirm what webhook endpoints the summarizer will send data to and ensure any external integrations are authorized and encrypted (HTTPS). Avoid sending raw contract text to untrusted endpoints. - Back up or review the manifest written to ~/.pilot/setups/legal-contract-review.json and set appropriate filesystem permissions if you handle sensitive legal documents.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.