Back to skill

Security audit

LYGO Champion: cryptosophia soulforger

Security checks across malware telemetry and agentic risk

Overview

This is a deprecated creative persona helper with local reference files and simple hash-check scripts, with no evidence of hidden access, persistence, or unsafe automation.

Install this only if you want a legacy creative persona prompt and local hash/provenance references. Treat the external LYGO-MINT verifier as a separate tool: review its permissions before using it, especially for ledger writing or backfilling posted anchors.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill instructs the agent to read local files under references/ and inspect canon.json, but it declares no permissions. Hidden file-read behavior creates a trust boundary issue: users may believe this is only a persona/helper prompt when it actually accesses workspace content. In an agent environment, undeclared reads can expose local data or normalize broader capability use without user awareness.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The skill is presented as a deprecated persona helper that mainly redirects users to another slug, but it also performs validation, parsing, and hash extraction from local reference files. This mismatch is dangerous because it obscures operational behavior behind innocuous documentation, reducing informed consent and making unexpected data access harder to notice during review. Even if the files are benign, concealed functionality increases the chance of abuse or accidental leakage.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation sequence uses a broad invocation and open-ended co-creation flow without clear scope limits, safety boundaries, or explicit exclusion of sensitive actions. In an agent skill, this can encourage over-bonding, authority framing, or unconstrained persona activation that may be used to steer later behavior in unintended ways, especially when paired with mystical or trust-inducing language.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The usage guidance relies on short natural-language trigger phrases such as “Mint this pack” and “Backfill anchors,” which are broad enough that an agent could invoke the verifier unintentionally when similar text appears in normal conversation or pasted content. While this file is only documentation, the phrasing increases the chance of accidental tool activation or misuse if the surrounding agent framework binds these phrases directly to privileged actions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.