Back to plugin

Security audit

LYGO Continuum

Security checks across malware telemetry and agentic risk

Overview

This skill is a local verification plugin that reads user-specified files to check completion claims, with no network, subprocess, or persistent behavior found.

Install only if you want agents to use local file checks before saying work is complete. Keep claim paths limited to the project you are working on, because the verifier can read any path the claims ask it to inspect. The observed temporary demo writes are local self-test behavior, not ongoing persistence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

61/61 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.