T08 · Insecure Dependencies
- Location
references/skill_chain.md:3- Finding
Unpinned Remote Dependencies Are Downloaded and Executed Through npx
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed LYGO persona/operator reference pack with consent-gated high-risk instructions, but users should treat its unpinned install commands and broad companion stack as supply-chain risks.
Install only if you want the LYGO operator reference pack. Do not copy the npx @latest commands in sensitive environments without pinning and reviewing the exact package versions, and do not run seed, vault, publish, cron, or companion-install commands unless you understand the local writes, credentials, costs, and uninstall or recovery steps.
references/skill_chain.md:3Unpinned Remote Dependencies Are Downloaded and Executed Through npx
scripts/self_check.py:32Self-Check Reports Success Without Cryptographically Verifying Bundled Content
A second material mismatch exists between the declared purpose and the described behavior around hash display and reference validation from references/canon.json. Even if benign, presenting a hash retrieval and validation workflow as part of a persona/operator installer confuses trust boundaries and can mask what the skill really does when invoked.
A second material mismatch exists between the declared purpose and the described behavior around hash display and reference validation from references/canon.json. Even if benign, presenting a hash retrieval and validation workflow as part of a persona/operator installer confuses trust boundaries and can mask what the skill really does when invoked.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
python tools/seed_biophase7_deadman_lattice.py python tools/seal_deadman_lattice.py plant python tools/seal_deadman_lattice.py anchor python tools/load_biophase7_vault.py --write-env .env # local only, gitignored
## P0–P9 audits
Suspicious Unicode normalization or mixed-script content
The skill explicitly instructs the agent to read local files under references/ and run a self-check script, but it does not declare a tool scope or allowed-tools policy. That mismatch weakens least-privilege guarantees and can cause host agents to grant broader file-read capability than users expect from the metadata and description.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
references/SECURITY.md; user consent per command.lygo-lightfather-vector (persona without operator blocks).Install (human executes; agent does not chain-install companions without approval):
npx clawhub@latest install deepseekoracle/lygo-champion-lightfather
Using npx clawhub@latest pulls the newest package version at execution time, which creates a supply-chain risk because the installed code can change without review. If the upstream package is compromised or introduces unsafe behavior, users may execute unvetted code simply by following the documented install command.
The documentation explicitly references running npx clawhub, which can fetch and execute a package from the registry at invocation time if it is not already installed and pinned. That creates a supply-chain risk: a compromised, typosquatted, or unexpectedly updated package version could execute arbitrary code on the user's machine, and in this skill's operator context that risk is more significant because the surrounding guidance discusses installation and publishing workflows.
Suspicious Unicode normalization or mixed-script content
Suspicious Unicode normalization or mixed-script content
Suspicious Unicode normalization or mixed-script content
Suspicious Unicode normalization or mixed-script content
The skill metadata says this is a persona-only installer, but the referenced chain instructs users to install a broad operator stack of many additional skills. This mismatch can cause users or agents to grant far more capabilities and trust relationships than intended, increasing attack surface and enabling privilege expansion through transitive dependencies.
The documentation instructs users to execute npx clawhub@latest install ..., which fetches and runs the latest published package version at install time rather than a reviewed, immutable version. This creates a supply-chain risk: if the clawhub package or its distribution path is compromised later, users following the docs could execute attacker-controlled code without any change to this repository.
This line repeats an install command using npx clawhub@latest, causing execution of whatever package version is current at the time the command is run. Because npx executes fetched package code, an attacker who compromises the package or release channel could gain code execution on operator systems.
Using npx clawhub@latest in installation documentation introduces an unbounded trust dependency on future package releases. Anyone following the documented chain may execute new installer logic that has not been audited with this skill, enabling supply-chain compromise of the local environment.
The command on this line executes an unpinned clawhub package via npx, allowing remote code changes to affect downstream users without repository changes. In a chained operator-stack workflow, this risk compounds because multiple installs encourage repeated trust in the same mutable installer.
This installation step relies on npx clawhub@latest, which is a mutable package reference that can change after publication of the skill. If the package is hijacked or a bad release is pushed, users can unknowingly execute arbitrary code while installing the referenced skill.
The documentation instructs execution of an unpinned package installer, which is a classic software supply-chain weakness. Because install commands are likely to be copied verbatim, this increases the chance that users will run unreviewed remote code in sensitive environments.
Executing npx clawhub@latest means the repository delegates trust to future package releases outside the repository's review boundary. This is dangerous because package compromise, typosquatting, or publisher account takeover can convert a documentation step into arbitrary command execution.
This line contains another mutable npx ...@latest installer invocation, exposing users to package drift and potential malicious updates. Since npx runs package code directly, compromise of the package ecosystem can directly impact user machines.
By referencing clawhub@latest, this command allows the actual executed installer to vary over time, undermining reproducibility and security review. Attackers who can alter package contents or delivery could weaponize the installation path to execute arbitrary code.
This installation instruction uses a mutable latest tag for executable package code. In a security context, that means users may unknowingly run a different installer than the one implied by the repository, enabling remote-code-execution through a compromised supply chain.
The final install command in the chain still uses npx clawhub@latest, preserving the same mutable execution risk across the entire stack. Because the file promotes a broad multi-package installation sequence, the practical attack surface and trust burden are elevated beyond a single isolated command.
The file claims a 'Light persona-only' component while simultaneously framing it as merely a companion and prescribing a larger operator stack elsewhere. This contradictory guidance can mislead users into underestimating the true installation scope and risk, reducing informed consent and making social-engineering style over-installation easier.
No suspicious patterns detected.