Back to skill

Security audit

Pilot Stream Data

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, disclosed Pilot Protocol streaming guide with some documentation and temporary-file cautions but no evidence of hidden or malicious behavior.

Before installing, confirm you trust the pilotctl binary and daemon you already use, avoid pasting sensitive stream data into examples without checking the destination, replace the fixed /tmp log with a private temporary file or direct processing, and stop any background listener or infinite producer loop when finished.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:40
Finding

Predictable Temporary Log File Enables Data Exposure and File Truncation

Content
View full analysis
/tmp/pilot-stream.log & ``` ### Technical Analysis The documented command redirects received stream data to a fixed path in the shared `/tmp` directory. Shell redirection opens the destination with truncation semantics and ordinarily follows an existing symbolic link. Because the path is predictable, another local process may prepare it before the command runs. Depending on operating-system symlink protections, directory permissions, file ownership, and the invoking user's privileges, this can cause the shell to truncate or overwrite a different file writable by that user. The newly created log file also inherits permissions from the invoking process's `umask`. With a permissive `umask`, other local users may be able to read potentially sensitive stream contents. ### Attack Path 1. A local attacker learns that the documented listener command uses `/tmp/pilot-stream.log`. 2. Before the command is executed, the attacker creates the predictable path or, where platform protections permit, places a symbolic link at that path targeting another file. 3. The user or agent executes the documented command. 4. The shell opens the path using output-redirection and truncation behavior. 5. The target file may be truncated or overwritten with stream data if it is writable under the invoking user's privileges. 6. Alternatively, if the log is created with permissive permissions, the attacker reads incoming stream records directly from the predictable file. Successful exploitation requires local access and is constrained by filesystem permissions and platform-level temporary-directory protections. ### Impact Assessment The issue does not grant privileges beyond those already held by the process running the command. Its potential effects are: - Disclosure of strea ...[truncated 472 chars]
Remediation
View remediation
"$STREAM_LOG" & listener_pid=$! wait "$listener_pid" ``` Additional hardening measures: 1. Avoid fixed filenames in shared temporary directories. 2. Set `umask 077` before creating files that may contain stream data. 3. Use `mktemp -d` so the log resides in a uniquely named directory accessible only to the current user. 4. Quote all generated paths to prevent shell word splitting. 5. Register cleanup handlers with `trap`. 6. If persistent logging is required, use an application-controlled directory with explicit ownership, `0700` directory permissions, and `0600` file permissions. 7. Consider processing the listener output directly instead of writing sensitive stream data to disk. ]]>
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The 'Do NOT use this skill when' section explicitly directs users away from pub/sub broadcast use cases. Later, the documentation presents a subscription command to a named topic as a supported usage pattern, which directly conflicts with that guidance and creates intent ambiguity.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest frames the skill narrowly as real-time NDJSON streaming and explicitly says not to use it for pub/sub broadcast or request/response patterns. However, the file documents pilotctl --json subscribe to a topic, which is a pub/sub capability, and the repeated send examples also blur into generic messaging rather than a strictly stream-oriented abstraction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.