T09 · Insecure Skill Coding Practices
Warning
- Location
SKILL.md:49- Finding
Unsafe Interpolation of External Task Identifiers into jq Expressions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed helper for sending parallel tasks through pilotctl, with some shell-safety issues in examples but no hidden or malicious behavior found.
Before installing, verify that pilotctl and the pilot-protocol environment are trusted, and harden the example snippets if you use them directly: pass task IDs to jq with --arg or --argjson, read peer addresses into arrays safely, validate discovered agents, and add polling timeouts.
SKILL.md:49Unsafe Interpolation of External Task Identifiers into jq Expressions
SKILL.md:63Unsafe Word Splitting and Pathname Expansion of Discovered Agent Addresses
No suspicious patterns detected.