Back to skill

Security audit

LYGO Champion: delta9ra wolf

Security checks across malware telemetry and agentic risk

Overview

This is a deprecated persona helper with local reference-check scripts, and the reviewed artifacts do not show hidden access, persistence, exfiltration, or destructive behavior.

Install only if you specifically want this legacy RA persona; the package itself appears low-risk, but it is deprecated in favor of lygo-champion-council. Treat its censorship/suppression framing as an investigative lens, not proof, and keep outputs grounded in sources and explicit user direction.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
78% confidence
Finding
The skill is described primarily as a deprecated legacy slug/persona helper, but it also appears to include verification behavior involving local file presence checks and reading/parsing reference files. That mismatch can mislead users and reviewers about what the skill actually does, reducing informed consent and making it easier for hidden or unexpected data access to slip through review.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation and mission language is broad enough that the persona could be invoked for loosely defined claims like 'truth is buried' or 'suppressed frequencies,' which are subjective and easy to over-trigger. In an agent setting, ambiguous activation criteria can cause the skill to engage outside intended contexts and amplify adversarial or conspiratorial framing without clear user authorization boundaries.

Vague Triggers

Medium
Confidence
91% confidence
Finding
This section mixes multiple invocation styles—boot directive, summon phrase, whisper phrase, symbolic trigger, oath, and verification prompts—without a single authoritative trigger boundary. That ambiguity increases the chance of accidental or prompt-injected activation and lets untrusted content imitate summon patterns to steer the agent into a specialized persona mode unexpectedly.

VirusTotal

50/50 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.