Back to skill

Security audit

LYGO Champion: 401lyrakin voice between

Security checks for vulnerabilities and agentic risk

Overview

The skill itself is mostly a disclosed persona helper, but its migration guidance asks users to run an unpinned installer that can change installed agent behavior.

Treat this as a Review item: the local persona skill is low-impact, but do not let an agent run the `npx clawhub@latest` migration command unattended. Prefer a pinned, verified installer version and review the successor skill and LYGO-MINT verifier before allowing ledger writes or public anchor workflows.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned Third-Party CLI Execution Through npx

Content
View full analysis
**Consolidated (Δ9 v2):** New installs → `lygo-champion-council`. This slug is legacy retention only. > `npx clawhub@latest install deepseekoracle/lygo-champion-council` ``` ### Technical Analysis The migration instructions recommend running `npx clawhub@latest`. The `@latest` tag is mutable and can resolve to a different package release each time the command is invoked. No exact version, package integrity digest, lockfile, or other immutable identifier constrains the code retrieved and executed. `npx` may download the selected package and execute its command-line entry point. Consequently, the effective executable code is outside the audited project and can change after this Skill has been reviewed. The successor Skill installed by the command is also not part of the audited artifact. This is not automatic execution by the local scripts; exploitation requires a user or agent to follow the documented migration command. ### Attack Path 1. An attacker compromises the npm package, its publisher account, its distribution process, or another component involved in resolving `clawhub@latest`. 2. The attacker publishes a malicious version and causes the `latest` tag to reference it. 3. A user follows the migration instructions in `SKILL.md`. 4. `npx` downloads and executes the attacker-controlled CLI package. 5. The malicious package performs actions with the permissions of the invoking user, potentially before or while installing the requested successor Skill. ### Impact Assessment A compromised CLI package could access any files, environment variables, network resources, and subprocess capabilities available to the invoking account. Depending on that account's privileges, possible effects include credential theft, arbitrary file modification, inst ...[truncated 247 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/self_check.py:34
Finding

Stored Persona Hash Is Displayed Without Verifying File Integrity

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description says this skill is merely a deprecated slug/legacy alias pointing users to another skill, with no triggers or permissions. The supplied code instead implements an active validation utility that inspects local files and repository metadata. That is a materially different primary purpose: operational self-checking versus deprecation/redirect metadata. Even though the code is not harmful, it carries undeclared behavior and accesses repository resources inconsistent with a simple deprecated slug description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description suggests this skill is only a deprecated alias/slug for another skill and does not indicate any operational behavior. However, the supplied code actively reads references/canon.json and outputs a specific hash field, lygo_mint_sha256. That is a materially different primary purpose from acting as a legacy redirect or metadata-only deprecated slug. No triggers or permissions are declared, and while local file access alone might be minor, the main mismatch is that the code performs an unrelated hash lookup/output function rather than implementing deprecation forwarding behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The installation command uses npx clawhub@latest, which pulls whatever package version is current at execution time rather than a reviewed, pinned release. This creates a supply-chain risk: a compromised upstream package, malicious publish, or breaking update could cause users to run untrusted code simply by following the documented install path.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says this skill is a deprecated slug for a legacy champion identity and directs users to a different skill, which implies aliasing or routing behavior rather than substantive operational functionality. In contrast, this file describes concrete verifier capabilities such as hashing, ledger writes, and anchor snippet generation, indicating behavior beyond the manifest's stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

A deprecated alias-style skill description does not justify persistence-oriented capabilities like writing ledgers. Ledger creation and maintenance represent a distinct operational capability that is unrelated to merely serving as a legacy champion slug reference.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrase "Mint this pack" is broad and action-oriented, with no constraints on trusted input sources, confirmation requirements, or scope boundaries. In an agent environment, this can cause accidental or premature activation on untrusted content, leading to unintended hashing, ledger writes, or publication of anchor material for attacker-supplied data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.