Back to skill

Security audit

LYGO Cyborg Onramp

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local onramp that prints install directions and links, but users should separately vet the external full package it recommends.

Install this only if you want a directory-style helper that prints links and manual install steps. Do not assume the linked FULL ZIP or suggested plugins are safe merely because this onramp is benign; inspect those separate packages before downloading or running them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill declares restrictive permissions (`network: false`, `shell: false`) but the content explicitly instructs users to open external URLs, install additional packages, and download a separate ZIP containing an 'unlocked autonomous agent stack'. Even though this file is documentation rather than executable code, it functions as an onramp to undeclared network and shell activity and could mislead operators or downstream tooling that relies on the manifest's permission claims.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest description advertises a 'FULL unlocked' agent stack and 'onramp' behavior without clearly bounded triggers or user-consent constraints, which can prime an agent platform or user to treat the skill as a gateway to broader capabilities than the package itself contains. In context, the wording is especially risky because it points to an external full package URL and uses expansive activation language that could encourage overbroad invocation or trust in a larger autonomous stack.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.