Back to skill

Security audit

Pilot Share

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward file-sharing skill, but users should verify destinations and file contents before running its send examples.

Install only if you intend to share files through Pilot Protocol. Before using it, confirm the destination agent ID, inspect the exact file or directory path being sent, avoid sensitive folders, and replace the directory archive snippet with a mktemp-based version that cleans up safely.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:45
Finding

Predictable Temporary Archive Enables Symlink-Based File Overwrite

Content
View full analysis
.tar.gz` as a symbolic link before the `tar` command executes. When `tar` opens the archive path for writing, it may follow the symbolic link and truncate or overwrite its target with archive data. Quoting the pathname protects against shell word splitting but does not prevent symbolic-link traversal or time-of-check/time-of-use attacks. The subsequent `rm` only removes the archive pathname and does not undo damage caused when the target was opened. ### Attack Path 1. The attacker learns or guesses the basename of a directory that the skill will share. 2. The attacker selects a target file writable by the account running the skill. 3. Before the workflow runs, the attacker creates a symbolic link such as: ```bash ln -s /path/to/writable/target /tmp/share.tar.gz ``` 4. The user or Agent runs the directory-sharing workflow with a directory named `share`. 5. `tar` opens `/tmp/share.tar.gz`, follows the attacker-controlled symbolic link, and overwrites or corrupts the target. 6. The workflow transmits the resulting archive path and then removes the temporary pathname, potentially obscuring the attack artifact without restoring the overwritten target. Successful exploitation require ...[truncated 790 chars]
Remediation
View remediation
&2 exit 1 } trap 'rm -f -- "$ARCHIVE"' EXIT tar czf "$ARCHIVE" \ -C "$(dirname -- "$DIR")" \ "$(basename -- "$DIR")" || exit 1 pilotctl --json send-file "$DEST" "$ARCHIVE" ``` Additional hardening measures: - Run the workflow as an unprivileged account and never invoke it through `sudo` unless strictly necessary. - Prefer a private temporary directory created with `mktemp -d` and restrictive permissions when multiple temporary artifacts are needed. - Check the exit status of both `tar` and `pilotctl` so failed archive creation cannot result in transmitting stale or unintended content. - Retain quoted variables and use `--` where supported to prevent pathnames beginning with a hyphen from being interpreted as command options. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill provides ready-to-run commands that send local files and archived directories to another agent, but it does not prominently warn that executing these examples transmits local data off-host. In an agentic context, that omission can lead to unintended disclosure of sensitive files, especially because the directory example packages and sends an entire folder and the workflow encourages automatic retries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.