Back to skill

Security audit

LYGO Continuum

Security checks for vulnerabilities and agentic risk

Overview

This local verification skill is mostly coherent, but untrusted capsules can steer local file reads and inject active or agent-directed content into generated outputs.

Install only if you are comfortable reviewing capsules before use. Always pass an explicit --base for the intended project, do not verify or hand off capsules from others without reading them, avoid opening generated witness-card HTML from untrusted capsules, and prefer a pinned installer instead of npx clawhub@latest.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/continuum.py:486
Finding

Untrusted capsule controls the filesystem verification base

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/continuum.py:592
Finding

Unescaped capsule fields allow active-content injection into witness cards

Content
View full analysis
str: """Minimal standalone witness card (embeddable).""" ok = True if verify_report is None else bool(verify_report.get("ok")) band = "HOLDS" if ok else "BROKEN" color = "#2dd4a8" if ok else "#f07178" rid = capsule.get("id", "?") rh = str(capsule.get("root_hash") or "")[:20] task = str(capsule.get("task_summary") or "")[:200] n = len(capsule.get("claims") or []) return f""" LYGO Continuum {rid} body{{margin:0;font-family:system-ui,Segoe UI,sans-serif;background:#0b0f14;color:#e6edf3;display:flex;min-height:100vh;align-items:center;justify-content:center}} .card{{max-width:420px;padding:1.5rem 1.75rem;border:1px solid #1e2a36;border-radius:16px;background:linear-gradient(145deg,#121a22,#0d1319);box-shadow:0 0 40px #0008}} .band{{display:inline-block;padding:.25rem .75rem;border-radius:999px;background:{color}22;color:{color};font-weight:700;letter-spacing:.06em;font-size:.8rem}} h1{{font-size:1.15rem;margin:.75rem 0 .25rem}} .meta{{color:#8b9aab;font-size:.85rem;line-height:1.5}} code{{color:#7dd3fc;font-size:.78rem;word-break:break-all}} .foot{{margin-top:1rem;font-size:.7rem;color:#5a6a7a}}
{band}

LYGO Continuum

{rid}
{task}
claims: {n} · root {rh}…
{SIG} · falsifiable work capsule
""" ``` ### Technical Analysis The `id` and `task_summary` fields originate in capsule JSON and are directly interpolated into HTML markup. Neither field is HTML-escaped. The 200-character truncation applied ...[truncated 1233 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/continuum.py:370
Finding

Attacker-controlled regular expressions can cause denial of service

Content
View full analysis
500: out["detail"] = "pattern too long" return out try: rx = re.compile(pattern, re.MULTILINE) except re.error as e: out["detail"] = f"bad regex: {e}" return out found = bool(rx.search(text)) ``` ### Technical Analysis Python's standard `re` engine uses backtracking. A short expression containing nested or ambiguous quantifiers can require exponential work on specially structured input. Limiting a pattern to 500 characters does not prevent this behavior because dangerous patterns can be very short. The expression is applied to the complete decoded file contents. There is no file-size limit, execution timeout, pattern-complexity validation, or process isolation. Catching exceptions does not help because catastrophic backtracking generally consumes CPU rather than raising an exception. ### Attack Path 1. An attacker supplies a capsule containing a pathological `regex_match` or `regex_not_match` claim. 2. The claim references a sufficiently large file under the selected base. 3. The victim verifies the capsule. 4. `rx.search(text)` enters excessive backtracking. 5. The CLI consumes substantial CPU and may remain unresponsive for an extended period, blocking the calling Agent or automation workflow. ### Impact Assessment Exploitation can cause process-level denial of service and high CPU utilization under the victim's account. It does not directly grant additional privileges or disclose data, but it can disrupt verification pipeli ...[truncated 53 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:58
Finding

Installation instructions execute an unpinned mutable dependency

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
scripts/continuum.py:548
Finding

Untrusted capsule content is promoted into Agent handoff instructions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/self_check.py (reported line 48)May include surrounding context.

python
base=root,
        )
        abs_esc = c.evaluate_claim(
            {"id": "y", "kind": "file_exists", "path": str(Path.home() / "secret.txt")},
            base=root,
        )
        glob_esc = c.evaluate_claim(

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

Using npx clawhub@latest install ... introduces a supply-chain risk because @latest is mutable and can resolve to a different package version over time. If the registry package or dependency chain is compromised, users may execute unreviewed code during installation even though the skill itself claims local-only behavior afterward.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module documentation asserts that writes are confined under --base or state/ with --i-consent, but the implementation includes an unrestricted override path. This is dangerous because downstream agents, operators, or policy engines may rely on the documented safety guarantees and grant the skill trust it has not actually earned, leading to unsafe file writes outside the workspace boundary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code explicitly permits arbitrary filesystem writes when --i-allow-any-out is supplied, which contradicts the stated confinement model of writes being limited to --base or state/ with --i-consent. In an agent setting, this weakens a key safety boundary: a prompt or workflow that can influence CLI arguments may cause the tool to overwrite files outside the intended workspace, including user config or project files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.