Back to skill

Security audit

Pilot Task Parallel

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed helper for sending parallel tasks through pilotctl, with some shell-safety issues in examples but no hidden or malicious behavior found.

Before installing, verify that pilotctl and the pilot-protocol environment are trusted, and harden the example snippets if you use them directly: pass task IDs to jq with --arg or --argjson, read peer addresses into arrays safely, validate discovered agents, and add polling timeouts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:49
Finding

Unsafe Interpolation of External Task Identifiers into jq Expressions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:63
Finding

Unsafe Word Splitting and Pathname Expansion of Discovered Agent Addresses

Content
View full analysis
Remediation
View remediation
0)' ) ``` Then validate the result before task submission: ```bash if ((${#AGENT_ARRAY[@]} == 0)); then printf '%s\n' "No valid GPU agents were discovered" >&2 exit 1 fi for agent in "${AGENT_ARRAY[@]}"; do # Replace this check with the authoritative pilot-protocol address format. [[ "$agent" =~ ^[A-Za-z0-9._:-]+$ ]] || { printf 'Invalid agent address: %q\n' "$agent" >&2 exit 1 } done ``` Additional hardening should include checking the exit statuses of both `pilotctl` and `jq`, rejecting duplicate addresses, setting a maximum number of discovered agents, and ensuring every later array expansion remains quoted as `"${AGENT_ARRAY[@]}"`. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.