pylot-api
Audited by Socket on Jul 25, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS. The skill’s purpose mostly matches its capabilities, but it routes sensitive tokens and conversation context to a private gateway whose operator and official documentation could not be publicly verified from the evidence. No confirmed malware or overt exploit behavior is present, but the unverifiable backend trust boundary, hidden-failure instruction, and operational side effects make this higher-risk than a normal documentation/API helper skill.
No explicit malicious payload behavior (backdoor, persistence, third-party exfiltration, or obfuscated logic) is evident in the provided fragment. The main concern is dual-use: it demonstrates how to authenticate to a privileged /admin/secrets endpoint to enumerate secret key metadata and to write secret values. If the bearer token or endpoint access is compromised or abused, this capability can materially enable credential reconnaissance and secret injection.