pilot-scientific-research-team-setup
Warn
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses the 'clawhub' utility to install several functional components, such as 'pilot-discover' and 'pilot-webhook-bridge', from an unverified external source. These installations are unversioned and occur without integrity verification.
- [PROMPT_INJECTION]: The pipeline ingests untrusted content from external scientific databases through the literature agent, creating a surface for indirect prompt injection where instructions hidden in research papers could influence downstream agents.
- [PROMPT_INJECTION]: Data flows between agents lack boundary markers or explicit instructions to ignore embedded commands, increasing the risk of instruction override during automated processing.
- [DATA_EXFILTRATION]: The setup configures a webhook bridge on the report agent that sends data to external endpoints on port 443, providing a potential egress channel for sensitive research data or credentials.
- [COMMAND_EXECUTION]: The skill relies on shell commands to set hostnames and write setup manifests directly to the user's home directory ('~/.pilot/setups/').
- [PROMPT_INJECTION]: There is a metadata discrepancy between the stated author 'vulture-labs' and the expected author identity 'TeoSlayer', which may indicate deceptive metadata or supply chain risk.
Audit Metadata