Back to skill

Security audit

LYGO Champion: volaris prism judgment

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly advisory deprecated persona helper with bundled reference files; the main caution is its unpinned migration command to install a successor skill via npx.

Installers should treat this as a legacy advisory persona pack. Do not run the `npx clawhub@latest` migration command unless you trust the current clawhub package and have reviewed the successor skill; prefer a pinned version or a review-before-install workflow.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned Third-Party Package Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8-9
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Code Snippet:

markdown
> **Consolidated (Δ9 v2):** New installs → `lygo-champion-council`. This slug is legacy retention only.
> `npx clawhub@latest install deepseekoracle/lygo-champion-council`

Technical Analysis

The documented migration command instructs users to invoke clawhub through npx with the mutable @latest version selector. If the package is not already available locally, npx may retrieve and execute package code from the configured npm registry. The exact code executed can therefore change after this skill has been reviewed.

The command also installs the external deepseekoracle/lygo-champion-council skill, whose contents are not included in this repository and were outside the audit scope. Neither the executable package version nor the successor artifact is pinned to an audited version or cryptographic digest.

This creates a supply-chain trust boundary in which package-publisher compromise, registry compromise, malicious future releases, or compromise of the externally installed skill could turn a legitimate-looking migration instruction into arbitrary code execution or unsafe agent behavior.

Attack Path

  1. An attacker compromises the clawhub package publisher, distribution channel, or a future release resolved by the latest tag. Alternatively, the externally hosted successor skill is compromised.
  2. A user follows the migration command in SKILL.md.
  3. npx resolves and downloads the package currently referenced by clawhub@latest.
  4. The downloaded package executes with the invoking user's operating-system privileges.
  5. The compromised package can perform arbitrary actions available to that account, or install attacker-controlled successor skill content.
  6. The installed content may continue affecting later invocations i ...[truncated 720 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace clawhub@latest with an explicitly pinned, reviewed version.
  2. Verify the downloaded package against a trusted lockfile or cryptographic integrity digest before execution.
  3. Pin the successor skill to an immutable release identifier and integrity hash rather than a mutable name or channel.
  4. Document the expected package registry, publisher identity, package version, and digest so users can validate provenance.
  5. Prefer a non-executing download-and-review workflow: retrieve the package, inspect its scripts and successor content, verify integrity, and only then execute installation.
  6. Run installation in a restricted environment with minimal filesystem access, no unnecessary credentials, and constrained network access.
  7. Avoid lifecycle scripts where possible, or explicitly disable them during package retrieval and enable execution only after review.
  8. Maintain an audited upgrade process so any version or digest change triggers a new security review.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A deprecated placeholder that actually reads local references and outputs a hash from canon.json performs concrete data-retrieval actions beyond what its description suggests. Even if the accessed files are intended references, hidden read behavior in a legacy package increases the chance of unintended data exposure or misuse by downstream agents.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A deprecated placeholder that actually reads local references and outputs a hash from canon.json performs concrete data-retrieval actions beyond what its description suggests. Even if the accessed files are intended references, hidden read behavior in a legacy package increases the chance of unintended data exposure or misuse by downstream agents.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill declares no explicit tool scope, yet its documented behavior references reading local files under references/ and extracting data from canon.json. That mismatch can cause the agent/runtime to grant or infer broader file-read behavior than users expect, which is risky in a package presented as a deprecated persona helper rather than an active file-processing skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The skill directs users to run npx clawhub@latest install ..., which relies on a floating latest version rather than a pinned, verified release. If the upstream package is compromised or changes behavior unexpectedly, users may execute unreviewed code during installation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
90% confidence
Finding

The JSON contains mixed-script or confusable Unicode text such as the display value "VΩLARIS", which can visually resemble ASCII identifiers while being a different string. This can enable spoofing, mismatched identity checks, logging confusion, or policy bypass if downstream systems compare, normalize, or display these values inconsistently.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
86% confidence
Finding

The heading uses visually confusable Unicode characters in "VΩLARIS" (for example, the Greek omega), which can enable spoofing, search/indexing mismatches, or inconsistent policy enforcement in systems that assume normalized ASCII text. In isolation this markdown is not executable, but mixed-script identifiers are a real security concern because they can mislead reviewers and tooling about whether two names are the same.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
90% confidence
Finding

The file uses mixed-script and non-ASCII characters such as "VΩLARIS" and "VΩLARIS 'Prism of Judgment'", which can create confusion, normalization mismatches, or deceptive lookalikes across tooling, policy engines, and allow/deny lists. In a security-sensitive agent ecosystem, this can be exploited to bypass simple string matching, cause identity ambiguity, or interfere with verification and governance workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The metadata says the slug is deprecated and redirects to another skill, but the file still ships an active persona specification with operational identity, role, anchor label, and verification instructions. This inconsistency can mislead users and automation into loading or trusting legacy content, creating policy drift, unauthorized invocation, or validation of the wrong persona package.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The documentation claims the type is "Persona Helper (pure advisor)," which suggests a non-acting, advisory-only role. The later mission language describes active gatekeeping and outcome control, creating an intent-level contradiction between passive advisory framing and interventionist behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.