Back to skill

Security audit

LYGO FractalWeaver

Security checks for vulnerabilities and agentic risk

Overview

This creative image-to-audio skill is mostly coherent, but it should be reviewed because it automatically loads local companion code and may write derived file information into persistent 3-Brain memory without a user-controlled opt-in.

Review before installing if you use LYGO 3-Brain or run skills in directories containing untrusted files. Run it in a clean working directory, avoid placing untrusted lyra_brain.py or resonance_engine.py beside it, and treat the automatic memory growth as persistent unless you remove or disable that code. Pin dependencies if reproducing or publishing the skill.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Warning
Location
fractalweaver.py:380
Finding

Automatic Import of an Untrusted Working-Directory Module and Persistent Memory Modification

Content
View full analysis

Vulnerability Details

File Location: fractalweaver.py, lines 380-390
Vulnerability Type: Untrusted module loading and non-consensual persistent state modification
Risk Level: Medium

Vulnerable Code:

python
# Grow to 3-Brain (recursive/self-similar nodes)
try:
    sys.path.insert(0, str(Path.cwd()))
    from lyra_brain import LyraThreeBrainMemory
    brain = LyraThreeBrainMemory(base_dir=Path.cwd(), use_advanced=True)
    summary = f"FractalWeaver: {image_path.name} → {preset} evolving weave | dim={lygo_meta['fractal_dimension']} sim={lygo_meta['self_similarity']} harmony={lygo_meta['recursive_harmony']}"
    nid = brain.grow(summary, source="fractalweaver")
    print(f"  Grown to 3-Brain node: {nid}")
except Exception:
    pass

Technical Analysis

The script explicitly inserts the current working directory at the beginning of sys.path and then imports lyra_brain. Python executes a module's top-level code during import. Consequently, an attacker who can place a file named lyra_brain.py in the directory from which the user runs FractalWeaver can cause arbitrary Python code to execute.

Prepending the working directory makes this location take precedence over trusted installed packages. This creates a local module-preloading or dependency-shadowing vulnerability. The broad exception handler does not mitigate the issue because malicious top-level code executes before an import failure could be handled. It also suppresses evidence that the integration failed or behaved unexpectedly.

After importing the module, the script automatically invokes brain.grow(...) without an explicit command-line option or confirmation. The persisted summary includes the image filename, which may be attacker-controlled. This creates a secondary memory-poisoning risk if downstream agent systems treat stored memory as trusted context.

A related implicit plugin-loading surface exists at fractalweaver.py, ...[truncated 1879 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the working-directory path modification:
    python
    sys.path.insert(0, str(Path.cwd()))
    
  2. Package lyra_brain as a pinned, verified dependency and import it through an authenticated package installation rather than an ambient working-directory lookup.
  3. Make memory integration explicitly opt-in, such as through a --grow-memory option. Do not modify persistent agent state during an ordinary audio-generation operation.
  4. Display the memory destination and proposed content before writing, and require confirmation for interactive use.
  5. Normalize and validate attacker-controlled fields before persistence. Store filenames as data rather than allowing them to be interpreted as instructions by downstream agents.
  6. Apply equivalent hardening to resonance_engine: use a packaged dependency or load a specifically configured file only after integrity verification.
  7. Catch narrowly defined exceptions and report failures instead of silently suppressing every exception.
  8. For extensibility, use an explicit plugin registry with allowlisted module names, expected versions, and cryptographic integrity checks.

T08 · Insecure Dependencies

Note
Location
README.md:11
Finding

Execution of Unpinned Third-Party Dependencies from Mutable Package Sources

Content
View full analysis

Vulnerability Details

File Location: README.md, line 11; SKILL.md, lines 78 and 143
Vulnerability Type: Unpinned dependency and mutable tool-version execution
Risk Level: Low

Vulnerable Documentation:

README.md, line 11:

bash
pip install opencv-python numpy soundfile

SKILL.md, line 78:

bash
pip install opencv-python numpy soundfile

SKILL.md, line 143:

bash
npx clawhub@latest publish .grok/skills/lygo-fractalweaver --slug lygo-fractalweaver --name "LYGO FractalWeaver" --version 0.1.0

Technical Analysis

The installation instructions do not pin reviewed versions of the Python dependencies and do not provide a lockfile or package hashes. Each installation can therefore resolve a different set of package releases and transitive dependencies.

The publishing command is more explicitly mutable because clawhub@latest instructs npm to retrieve and execute whichever release currently owns the latest distribution tag. The effective code executed by this command can change after the skill has been audited.

This is a supply-chain weakness rather than evidence that any named dependency is currently malicious. Exploitation requires compromise of an upstream package, registry account, distribution tag, package-resolution path, or network/package source trusted by the user.

Attack Path

  1. An attacker compromises an upstream package release, maintainer account, registry distribution tag, or dependency-resolution source.
  2. A user follows the documented pip install or npx ...@latest command.
  3. The package manager resolves the unpinned or mutable package to the attacker-controlled release.
  4. Package installation hooks, imported native components, or the npx executable run under the user's account.
  5. The compromised dependency can perform actions available to that user before FractalWeaver itself is executed.

Impact Assessment

A compromised ...[truncated 614 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin exact reviewed Python dependency versions in a requirements file:
    text
    opencv-python==REVIEWED_VERSION
    numpy==REVIEWED_VERSION
    soundfile==REVIEWED_VERSION
    
  2. Generate a lockfile that includes transitive dependencies.
  3. Require cryptographic hashes, for example through pip install --require-hashes -r requirements.txt.
  4. Pin the npm tool to a reviewed exact version instead of using @latest:
    bash
    npx clawhub@EXACT_REVIEWED_VERSION publish ...
    
  5. Commit the applicable lockfile and verify package integrity in continuous integration.
  6. Use trusted registries over authenticated TLS and document the expected package sources.
  7. Run installation and publishing tools with minimum privileges and isolate them in a virtual environment or disposable build container.
  8. Keep publishing credentials scoped narrowly and unavailable to dependency-installation steps whenever possible.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
3. Copy the contents of this skill (`fractalweaver.py`, `SKILL.md`, etc.) into it. If you have the lygo-resonance skill, copy or symlink its `resonance_engine.p

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill describes writing multiple local outputs such as WAV, JSON, stems, and MIDI files, but it declares no explicit permissions or allowed-tools scope. In an agent ecosystem, that mismatch can cause the skill to run with broader-than-expected file-write capability or make reviewers unable to validate what filesystem access is intended.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The publication instruction uses 'npx clawhub@latest', which fetches and executes the latest package version at runtime. If the upstream package, dependency chain, or registry resolution is compromised, users may execute unexpected code during publish/update workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code automatically persists a derived summary about the processed input into an external or separate memory subsystem ('3-Brain') that is unrelated to the core image-to-audio task. Even if the stored content is brief, this creates undisclosed retention and cross-context data propagation, which can leak filenames, workflow details, or sensitive project context and violates least surprise for a local media tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The optional 3-Brain memory write occurs automatically and silently, without a user-facing flag, confirmation, or manifest-level disclosure. In this skill context, that makes the issue more serious because users expect a local creative transformation tool, not background persistence into another subsystem that could retain sensitive filenames or semantic summaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Modifying sys.path at runtime and importing an unrelated memory module expands the trust boundary and allows local module resolution from the current working directory, which can load unintended or attacker-planted code. In a skill whose stated function is fractal analysis and audio generation, this hidden import-path manipulation is unnecessary and increases the risk of arbitrary code execution or unauthorized side effects.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The docstring claims a local-first, review-before-external-use posture, but the implementation automatically performs a memory-growth action without review or opt-in. This mismatch is dangerous because users may rely on the stated privacy posture while the tool silently persists derived data elsewhere, undermining informed consent and trust.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This code writes a detailed profile file containing the source image path, extracted features, and generation metadata to disk. Although the module docstring mentions a JSON profile output, there is no immediate user-facing disclosure, confirmation, or inline warning at the write site, so users may not realize analysis metadata is being persisted alongside the WAV output.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.