Back to skill

Security audit

Pilot Sync

Security checks for vulnerabilities and agentic risk

Overview

The skill is a file-sync helper, but its example overclaims safe two-way conflict handling and includes unsafe shell code that can execute commands from crafted filenames.

Review before installing or using. Only run this against a tightly controlled directory and trusted remote peer, and do not rely on it for real bidirectional sync or conflict recovery as written. The manifest-generation example should be fixed before use because malicious or unusual filenames could trigger shell command execution.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:62
Finding

Arbitrary Shell Command Injection Through Crafted Filenames

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises bidirectional synchronization with conflict detection, but the documented implementation only performs outbound sends and passive listing of received files. This mismatch is dangerous because operators may rely on it for consistency or recovery and unknowingly lose updates, fail to propagate remote changes, or assume conflicts are handled when they are not.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The examples transmit file contents and detailed manifests, including filenames, hashes, and timestamps, to a remote peer without any warning about privacy, sensitivity, or scope. In a file synchronization skill, this context increases risk because users may point the tool at broad directories and unintentionally exfiltrate confidential data or metadata across the network.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow example explicitly claims 'Bidirectional sync with conflict detection' while the script only builds a local manifest, sends it, and watches for local changes to transmit outward. Users following this example could deploy it expecting safe two-way sync and conflict handling, leading to silent divergence, overwrites by external processes, or missed remote updates.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.