Security audit
Pilot Service Agents Infra
Security checks for vulnerabilities and agentic risk
Overview
This is an instruction-only Pilot Protocol skill for querying infrastructure agents with disclosed network use and no hidden executable code.
Install this only if you trust your pilotctl binary, Pilot daemon, and the network 9 overlay agents. Avoid sending secrets, credentials, or sensitive local details in prompts or filters, especially for /summary or free-text requests that may be processed by service agents or Gemini.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
