Back to skill

Security audit

Pilot Mcp Bridge

Security checks for vulnerabilities and agentic risk

Overview

The skill is a network bridge blueprint whose purpose is clear, but it under-discloses important network trust boundaries and includes unsafe command templates plus a hard-coded external registry/beacon endpoint.

Review this skill before installing. Only use it with Pilot infrastructure you trust, avoid the hard-coded registry/beacon unless you know who operates it, and ensure any MCP wrapper validates inputs and invokes pilotctl without shell interpolation. Run the daemon with least privilege and avoid exposing listeners or gateway mappings on untrusted networks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:48
Finding

Shell Command Injection Through Unsafely Interpolated MCP Arguments

Content
View full analysis
--message ""` - `pilot_send_message`: Run `pilotctl --json send-message --data ""` - `pilot_recv`: Run `pilotctl --json recv ` - `pilot_listen`: Run `pilotctl --json listen ` Discovery: - `pilot_find`: Run `pilotctl --json find ` - `pilot_lookup`: Run `pilotctl --json lookup ` Pub/Sub: - `pilot_publish`: Run `pilotctl --json publish --data ""` - `pilot_subscribe`: Run `pilotctl --json subscribe ` Gateway: - `pilot_gateway_start`: Run `pilotctl --json gateway start` - `pilot_gateway_map`: Run `pilotctl --json gateway map ` ``` ### Technical Analysis The skill blueprint places MCP tool arguments directly into command-line templates without requiring validation, escaping, or shell-free process execution. Arguments such as `target`, `port`, `msg`, `hostname`, `topic`, `node_id`, and `local-ip` may therefore cross an unsafe boundary from an MCP caller into a command shell. Quoting message values with double quotes is not sufficient protection. POSIX-compatible shells still evaluate command substitution such as `$(...)` and backticks inside double-quoted strings. Unquoted parameters can additionally introduce separators, redirections, pipelines, substitutions, or extra command-line arguments. The project does not contain the referenced `mcp_pilot_server.py`, so direct exploitation cannot be verified against an implementation. Nevertheless, implementing the documented templates using shell command strings would create a command-injection vulnerability. ### Attack Path 1. An attacker obtains access to one of the exposed MCP tools or causes an agent to invoke it with attacker-controlled data. 2. The attacker ...[truncated 1058 chars]
Remediation
View remediation

other

Warning
Location
SKILL.md:66
Finding

Hard-Coded Unverified External Registry and Beacon Endpoint

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents starting a networked daemon, exposing MCP tools, and performing connect/send/listen/gateway operations, but it does not warn users about network exposure, message confidentiality, trust boundaries, or the system impact of opening listeners and gateway mappings. In an agent-skills context, this omission is risky because operators may invoke the documented commands without understanding that they can transmit data off-host, expose services, or interact with untrusted peers.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.