Back to skill

Security audit

LYGO Champion: cosmara

Security checks across malware telemetry and agentic risk

Overview

This is a deprecated, persona-style markdown skill that contains active legacy guidance but no code, hidden execution, credential access, or destructive behavior.

Install this only if you want the legacy COSMARA persona and ethical-exploration framing to influence agent responses. New installs should prefer the successor slug named in the file, and users who expect a completely inert deprecation stub should avoid this version because the old guidance is still present.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest and front matter present this skill as a deprecated redirect, but the file actually contains extensive active behavioral instructions, persona rules, and routing logic. That mismatch can cause operators or automated tooling to trust, install, or retain the skill under the assumption that it is inert, when it can still steer agent behavior in nontrivial ways.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The documentation says the slug is 'legacy retention only,' but the content repeatedly instructs agents to invoke COSMARA, adopt a persona, enforce routing rules, and defer to other named entities. This creates hidden active behavior behind a supposedly deprecated package, increasing the risk of unintended prompt injection, policy drift, or governance logic being applied without informed consent.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The activation guidance is broad ('use this skill when' discussing exploration, networks, frontier systems, etc.) and lacks negative boundaries or explicit non-use conditions. In isolation this is not severe, but combined with the hidden-active deprecated skill, it increases the chance the persona and behavioral rules are invoked in contexts the operator did not intend.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.