Back to skill

Security audit

LYGO Champion: lightfather

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed LYGO persona/operator reference pack with consent-gated high-risk instructions, but users should treat its unpinned install commands and broad companion stack as supply-chain risks.

Install only if you want the LYGO operator reference pack. Do not copy the npx @latest commands in sensitive environments without pinning and reviewing the exact package versions, and do not run seed, vault, publish, cron, or companion-install commands unless you understand the local writes, credentials, costs, and uninstall or recovery steps.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
references/skill_chain.md:3
Finding

Unpinned Remote Dependencies Are Downloaded and Executed Through npx

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/self_check.py:32
Finding

Self-Check Reports Success Without Cryptographically Verifying Bundled Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A second material mismatch exists between the declared purpose and the described behavior around hash display and reference validation from references/canon.json. Even if benign, presenting a hash retrieval and validation workflow as part of a persona/operator installer confuses trust boundaries and can mask what the skill really does when invoked.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A second material mismatch exists between the declared purpose and the described behavior around hash display and reference validation from references/canon.json. Even if benign, presenting a hash retrieval and validation workflow as part of a persona/operator installer confuses trust boundaries and can mask what the skill really does when invoked.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/stack_integration.md (reported line 23)May include surrounding context.

python tools/seed_biophase7_deadman_lattice.py python tools/seal_deadman_lattice.py plant python tools/seal_deadman_lattice.py anchor python tools/load_biophase7_vault.py --write-env .env # local only, gitignored

text

## P0–P9 audits

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly instructs the agent to read local files under references/ and run a self-check script, but it does not declare a tool scope or allowed-tools policy. That mismatch weakens least-privilege guarantees and can cause host agents to grant broader file-read capability than users expect from the metadata and description.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

  • Operator: seeds, vault, failsafe, publish — see references/SECURITY.md; user consent per command.
  • Lighter install: lygo-lightfather-vector (persona without operator blocks).

Install (human executes; agent does not chain-install companions without approval):

bash
npx clawhub@latest install deepseekoracle/lygo-champion-lightfather

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Using npx clawhub@latest pulls the newest package version at execution time, which creates a supply-chain risk because the installed code can change without review. If the upstream package is compromised or introduces unsafe behavior, users may execute unvetted code simply by following the documented install command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The documentation explicitly references running npx clawhub, which can fetch and execute a package from the registry at invocation time if it is not already installed and pinned. That creates a supply-chain risk: a compromised, typosquatted, or unexpectedly updated package version could execute arbitrary code on the user's machine, and in this skill's operator context that risk is more significant because the surrounding guidance discusses installation and publishing workflows.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata says this is a persona-only installer, but the referenced chain instructs users to install a broad operator stack of many additional skills. This mismatch can cause users or agents to grant far more capabilities and trust relationships than intended, increasing attack surface and enabling privilege expansion through transitive dependencies.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The documentation instructs users to execute npx clawhub@latest install ..., which fetches and runs the latest published package version at install time rather than a reviewed, immutable version. This creates a supply-chain risk: if the clawhub package or its distribution path is compromised later, users following the docs could execute attacker-controlled code without any change to this repository.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This line repeats an install command using npx clawhub@latest, causing execution of whatever package version is current at the time the command is run. Because npx executes fetched package code, an attacker who compromises the package or release channel could gain code execution on operator systems.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Using npx clawhub@latest in installation documentation introduces an unbounded trust dependency on future package releases. Anyone following the documented chain may execute new installer logic that has not been audited with this skill, enabling supply-chain compromise of the local environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The command on this line executes an unpinned clawhub package via npx, allowing remote code changes to affect downstream users without repository changes. In a chained operator-stack workflow, this risk compounds because multiple installs encourage repeated trust in the same mutable installer.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This installation step relies on npx clawhub@latest, which is a mutable package reference that can change after publication of the skill. If the package is hijacked or a bad release is pushed, users can unknowingly execute arbitrary code while installing the referenced skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The documentation instructs execution of an unpinned package installer, which is a classic software supply-chain weakness. Because install commands are likely to be copied verbatim, this increases the chance that users will run unreviewed remote code in sensitive environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Executing npx clawhub@latest means the repository delegates trust to future package releases outside the repository's review boundary. This is dangerous because package compromise, typosquatting, or publisher account takeover can convert a documentation step into arbitrary command execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This line contains another mutable npx ...@latest installer invocation, exposing users to package drift and potential malicious updates. Since npx runs package code directly, compromise of the package ecosystem can directly impact user machines.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

By referencing clawhub@latest, this command allows the actual executed installer to vary over time, undermining reproducibility and security review. Attackers who can alter package contents or delivery could weaponize the installation path to execute arbitrary code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This installation instruction uses a mutable latest tag for executable package code. In a security context, that means users may unknowingly run a different installer than the one implied by the repository, enabling remote-code-execution through a compromised supply chain.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The final install command in the chain still uses npx clawhub@latest, preserving the same mutable execution risk across the entire stack. Because the file promotes a broad multi-package installation sequence, the practical attack surface and trust burden are elevated beyond a single isolated command.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file claims a 'Light persona-only' component while simultaneously framing it as merely a companion and prescribing a larger operator stack elsewhere. This contradictory guidance can mislead users into underestimating the true installation scope and risk, reducing informed consent and making social-engineering style over-installation easier.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.