Back to skill

Security audit

LYGO Champion: scenar paradox

Security checks across malware telemetry and agentic risk

Overview

This is a small deprecated persona helper with limited local reference files and no evidence of hidden execution, credential access, exfiltration, or destructive behavior.

Before installing, note that this is a deprecated persona pack and new installs are directed to the successor. The included scripts are limited to local package verification, but the separate LYGO-MINT verifier link is another tool with its own behavior and should be reviewed independently before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
82% confidence
Finding
The top-level description frames the skill as only a deprecated pointer to a successor, but the embedded behavior indicates it may inspect local files, parse `references/canon.json`, validate content in `verifier_usage.md`, and print values derived from local artifacts. This mismatch can mislead users and security tooling about what the skill actually does, reducing informed consent and increasing the chance of unintended local data exposure or trust abuse.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.