Back to skill

Security audit

LYGO Champion: aetheris viral truth

Security checks across malware telemetry and agentic risk

Overview

This is a deprecated persona/helper skill with disclosed local reference files and no evidence of hidden execution, data exfiltration, or destructive behavior.

Install this only if you want the legacy LYGO persona helper. Prefer the named successor for new use, and review the separate verifier before using minting or anchor features because that separate workflow may write persistent ledger records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
79% confidence
Finding
The skill is described primarily as a deprecated persona helper, but it also instructs verification behavior involving checking local files and extracting a hash from canon.json. This hidden or under-declared operational behavior can mislead reviewers and users about what the skill actually accesses, increasing the chance of unintended file access and weakening trust and review controls.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The pack includes a broad trigger phrase ('Show your LYGO hash' / 'Generate an Anchor Snippet for this pack') intended to elicit specific behavior from an agent without clear scoping or user-consent gating. In a persona/helper skill, such invocation language can cause unintended activation or prompt steering, especially because the surrounding content frames the persona as contagious/propagating and encourages operational responses.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The instructions tell a user to run actions that write append-only and canonical ledgers and later backfill anchors, which can create persistent records or modify local/project state without any explicit warning, confirmation step, or scope limitation. In an agent setting, this is risky because users may interpret the commands as read-only verification, while the skill actually directs the agent to perform durable writes and external-posting related follow-up actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.