Back to skill

Security audit

LYGO Champion: sephrael echo walker

Security checks for vulnerabilities and agentic risk

Overview

This is a deprecated persona-helper skill with narrow local reference files and no automatic actions, though users should verify the replacement install command before running it.

Before installing, treat this as a legacy alias and prefer the maintained successor only after confirming the publisher and package version. Avoid blindly running the npx @latest command in sensitive environments; inspect or pin the installer when possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:6
Finding

Unpinned External Package Execution Creates a Supply-Chain Risk

Content
View full analysis
**Consolidated (Δ9 v2):** New installs → `lygo-champion-council`. This slug is legacy retention only. > `npx clawhub@latest install deepseekoracle/lygo-champion-council` ``` ### Technical Analysis The installation instructions use the mutable `latest` tag for the externally supplied `clawhub` package and direct users to install a separately maintained Skill that is not included in the audited project. Because neither dependency is pinned to a reviewed immutable version, commit, package digest, or signature, the code retrieved when a user runs this command may differ from the code available when this Skill was audited. An attacker who compromises the package registry entry, publisher account, upstream repository, or successor Skill could replace the effective installation payload. The command is documented rather than automatically invoked by the included scripts, so exploitation requires a user or agent to follow the installation instruction. ### Attack Path 1. An attacker compromises the `clawhub` package, its publishing account, or the externally maintained successor Skill. 2. The attacker publishes a modified version under the mutable release referenced by `@latest`, or modifies the successor Skill fetched during installation. 3. A user or agent follows the documented `npx` command. 4. `npx` downloads and executes the currently published package rather than an immutable, previously reviewed version. 5. The compromised installer or installed Skill executes attacker-controlled behavior with the permissions of the invoking process. ### Impact Assessment Successful exploitation could allow arbitrary behavior supported by the downloaded installer or successor Skill under the invoking user's privileges. Depending on the external payload ...[truncated 422 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/self_check.py:34
Finding

Integrity Check Trusts Stored Hash Without Verifying Persona Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Although framed as a legacy marker, the skill instructs reading references/canon.json and exposing a stored hash value, which is concrete utility behavior not disclosed by the declared purpose. Even if the exposed value is not highly sensitive, undisclosed data access/output behavior erodes least surprise and can normalize similar patterns that leak more sensitive local data in other skills.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Although framed as a legacy marker, the skill instructs reading references/canon.json and exposing a stored hash value, which is concrete utility behavior not disclosed by the declared purpose. Even if the exposed value is not highly sensitive, undisclosed data access/output behavior erodes least surprise and can normalize similar patterns that leak more sensitive local data in other skills.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill references local files under references/ and instructs showing a hash from references/canon.json, which implies filesystem read capability while declaring no explicit tool scope or permissions. Hidden or undeclared file access weakens trust boundaries and can enable broader data exposure if the runtime grants implicit read access beyond the intended files.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Using npx clawhub@latest pulls whatever version is current at execution time, creating a supply-chain and reproducibility risk. If the upstream package is compromised or a breaking/malicious release is published, users of the skill could execute unreviewed code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.