Back to skill

Security audit

LYGO Champion: 401lyrakin voice between

Security checks across malware telemetry and agentic risk

Overview

This deprecated persona skill is advisory and self-contained, with the main caveat that a separate verifier it recommends may write local ledger files if the user installs and runs it.

Use this as an advisory persona, not as an automation tool. If you follow its recommendation to install or run the separate LYGO-MINT verifier, first confirm where that verifier writes ledger files, pass only the content or file path you intend to mint, and treat any posted anchor snippets or backfilled URLs as potentially public.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrase "Mint this pack" is broad and lacks clear scope limits such as what inputs are allowed, whether local files may be read, or what directories/locations are in-bounds. In an agent setting, ambiguous natural-language triggers can cause unintended processing of sensitive content or user confusion about what data will be hashed, ledgered, or published as anchors.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation states that the verifier will write append-only and canonical ledgers, but it does not warn users that local data will be modified or where those writes occur. In an agent workflow, undisclosed file writes can surprise users, alter repositories or working directories, and create integrity or privacy issues if ledger contents include sensitive metadata.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.