Back to skill

Security audit

LYGO Excavationpro Music Lattice

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed music-portal routing and verification helper with read-only local scripts and human-gated publishing actions.

Install this if you want an agent to route and verify the Excavationpro music portal. Be careful with operator workflows: only set LYGO_STACK_ROOT to a trusted local stack, review any stack_cli command before running it, and approve HF, git, or donation-related actions only when you intended them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The intent map contains short, generic phrases such as "listen", "verify", "paypal", and "donate" that can match ordinary user requests and trigger this skill unintentionally. Because the skill exposes operational actions and external destinations, overly broad routing increases the chance of mis-invocation, unexpected navigation to third-party services, or unintended execution of adjacent workflow steps in a larger agent system.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.