Back to skill

Security audit

LYGO Champion: sancora unified minds

Security checks across malware telemetry and agentic risk

Overview

This is a legacy persona helper with small local verification helpers and no evidence of hidden network access, credential use, persistence, or destructive behavior.

This appears safe to install as a persona/reference skill. Treat it as deprecated and prefer the stated successor for new use; only run or use the separate verifier workflow if you intentionally want LYGO-MINT hash or anchor behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
76% confidence
Finding
The skill is presented as a deprecated persona helper with no automatic actions, but the analyzed behavior includes local file validation, parsing canon.json, checking verifier strings, and printing a hash. That mismatch can mislead users and policy systems about what the skill actually does, undermining trust boundaries and enabling unintended data exposure or execution of verification-related logic under an innocuous persona label.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The phrase 'When invoked, output:' defines behavior but never specifies who may invoke the persona, under what conditions, or with what bounds. In a persona/helper skill, this ambiguity can cause the agent to apply the transformation too broadly, potentially overriding normal task framing or injecting this persona workflow into unrelated prompts, which can lead to unintended instruction interference and unreliable behavior.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.