Back to skill

Security audit

Pilot Load Balancer

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent load-balancing skill for pilot worker pools, with some shell-example safety issues users should fix before production use.

Install only if you use pilot-protocol worker pools and are comfortable with the agent sending task-assignment messages to those workers. Before production use, replace the /tmp state file with a private locked state location and build JSON payloads with a JSON-aware encoder.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:40
Finding

Unsafe Predictable State File in a Globally Writable Temporary Directory

Content
View full analysis
/dev/null || echo 0) NEXT_WORKER=$(echo "$WORKERS" | jq -r ".[$ROBIN_INDEX].address") pilotctl --json send-message "$NEXT_WORKER" \ --data "{\"type\":\"task_assignment\",\"task_id\":\"$TASK_ID\"}" echo "$(( (ROBIN_INDEX + 1) % WORKER_COUNT ))" > /tmp/load-balancer-index.txt ``` ### Technical Analysis The documented round-robin implementation reads from and writes to the fixed path `/tmp/load-balancer-index.txt`. Because `/tmp` is ordinarily writable by all local users, an attacker can pre-create this file, replace it with a symbolic link, or alter its contents between the read and write operations. No ownership, file type, permission, or symbolic-link validation is performed. The state update is also not atomic and does not use locking, allowing concurrent invocations to race and overwrite one another. In addition, the retrieved value is inserted into a `jq` expression without first confirming that it is a valid non-negative integer. ### Attack Path 1. A local attacker predicts the fixed path `/tmp/load-balancer-index.txt`. 2. The attacker either: - writes a manipulated worker index into the file; - replaces the file with a symbolic link to another path writable by the victim; or - modifies the file during a concurrent read-modify-write operation. 3. A user invokes the documented load-balancing commands. 4. The commands consume attacker-controlled routing state and may select an unintended worker. 5. During the final shell redirection, the process follows any attacker-created symbolic link and truncates or overwrites the linked destination using the invoking user's permissions. ### Impact Assessment A successful attack can manipulate worker selection, corrupt round-robin state, disrupt task di ...[truncated 306 chars]
Remediation
View remediation
0 )) || exit 1 (( ROBIN_INDEX < WORKER_COUNT )) || ROBIN_INDEX=0 NEXT_INDEX=$(( (ROBIN_INDEX + 1) % WORKER_COUNT )) TEMP_FILE=$(mktemp "$STATE_DIR/index.XXXXXX") chmod 600 "$TEMP_FILE" printf '%s\n' "$NEXT_INDEX" > "$TEMP_FILE" mv -- "$TEMP_FILE" "$STATE_FILE" ) 9>"$LOCK_FILE" ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:43
Finding

JSON Injection Through Unescaped Task Identifiers

Content
View full analysis
/tmp/load-balancer-index.txt ``` ```bash LEAST_LOADED=$(echo "$WORKER_STATUS" | jq -r 'sort_by(.active_tasks) | first | .worker') pilotctl --json send-message "$LEAST_LOADED" \ --data "{\"type\":\"task_assignment\",\"task_id\":\"$TASK_ID\"}" ``` ### Technical Analysis `TASK_ID` is interpolated directly into a JSON string without JSON encoding. A task identifier containing quotation marks, backslashes, or control characters can invalidate the message or alter its structure. For example, a value conceptually shaped like: ```text x","priority":"admin","extra":" ``` would introduce additional fields into the generated JSON object. Whether a particular injected field has security significance depends on the receiving worker's message schema and authorization checks, which are not included in the audited project. Nevertheless, the sender does not preserve the task identifier as a data value, creating a confirmed structured-data injection weakness. Shell command substitution is not directly triggered merely by metacharacters contained in the expanded variable at this location. The vulnerability is JSON injection and malformed-message generation, not demonstrated shell command injection. ### Attack Path 1. An attacker gains influence over a task identifier supplied through `TASK_ID`. 2. The attacker includes JSON metacharacters such as quotes and backslashes in the identifier. 3. The shell interpolates the value directly into the `--data` argument. 4. `pilotctl` receives malformed or attacker-modified JSON. 5. The message is sent to the selected worker. 6. Depending on the worker's parser and accep ...[truncated 573 chars]
Remediation
View remediation
&2 exit 1 } payload=$(jq -nc \ --arg task_id "$TASK_ID" \ '{type: "task_assignment", task_id: $task_id}') pilotctl --json send-message -- "$NEXT_WORKER" \ --data "$payload" ``` Apply the same encoded-payload construction to the least-connections workflow. Receiving workers should additionally validate the complete message schema, reject unknown fields where practical, enforce authorization independently of sender-provided attributes, and avoid treating task identifiers as executable content. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file includes concrete commands that transmit task data to other nodes via pilotctl send-message, but the skill description does not explicitly warn users that task identifiers and routing metadata will be sent over the network to worker peers. Because SQP-2 applies to markdown files, the omission of a disclosure about data transmission is a relevant safety concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The example loops over tasks and sends messages to multiple workers in the background, causing bulk remote actions across the worker pool. The markdown does not warn that running this example will initiate multiple concurrent network operations that may affect distributed system state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.