T07 · Tool Hijacking and Spoofing
- Location
glyph2resonance.py:367- Finding
Untrusted Local Module Loading Enables Arbitrary Code Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly performs local glyph-to-audio generation, but it automatically loads local integration modules and can write into a persistent memory system, so it should be reviewed before installation.
Install only in a controlled workspace. Treat any local lyra_brain.py or resonance_engine.py as trusted code before running, avoid processing attacker-supplied filenames if 3-Brain is present, and prefer pinned dependency and ClawHub tool versions. Review or disable the automatic memory-growth block if you want a purely local glyph-to-audio converter.
glyph2resonance.py:367Untrusted Local Module Loading Enables Arbitrary Code Execution
glyph2resonance.py:366Automatic Persistent Memory Write Accepts Attacker-Controlled Filename Content
SKILL.md:140Unpinned Third-Party Installation and Publishing Commands Create Supply-Chain Risk
The skill is presented primarily as a local glyph-to-audio transformer, but the documentation also describes persistence to memory systems, queue/task integration, agent orchestration, and downstream profile generation beyond simple sonification. This mismatch is dangerous because users or agents may approve the skill expecting limited local processing while it performs broader ecosystem side effects, increasing the chance of unintended data retention, propagation, or automation.
Referenced artifact was not completely inspected
3. Copy the contents of this skill (`glyph2resonance.py`, `SKILL.md`, etc.) into it. If you have the lygo-resonance skill installed, copy or symlink its `resona
Suspicious Unicode normalization or mixed-script content
The skill describes capabilities that write files locally, including WAV, JSON, MIDI, stems, generated images, and possible memory-growth artifacts, yet it declares no explicit tool scope or permissions. In agent ecosystems, missing scope declarations can cause overbroad execution assumptions and make file-writing side effects occur without clear user awareness or policy gating.
The documentation instructs users to run 'npx clawhub@latest publish ...', which pulls and executes the latest package version at runtime. This creates a supply-chain risk because a compromised or malicious upstream release could execute arbitrary code during publish operations, especially in environments where users copy commands directly from the skill.
Suspicious Unicode normalization or mixed-script content
The skill performs behavior beyond its declared sonification purpose by attempting to import a local module and persist derived content into a '3-Brain' memory system automatically. This creates an unexpected side effect on the host agent environment, and because it modifies external state using current working directory context, it can contaminate memory, create persistence, or interact with attacker-controlled local modules.
Automatic mutation of agent memory context is not necessary for image-to-audio conversion and violates least surprise. In an agent setting, silently appending generated summaries to memory can poison future reasoning, leak filenames/metadata into persistent context, and create cross-task influence without user approval.
At L123 the documentation says outputs are 'local-first' and external use should be gated, implying a restrained/local workflow. Later lines L140-L143 provide direct ClawHub publishing steps, and earlier lines also promote external companion and donation URLs, which weakens that local-only framing and creates a mild intent/documentation inconsistency.
The module documentation states 'Outputs: - Stereo WAV soundscape'. However, in the built-in synthesis path the code collapses the generated stereo layers to mono at L238 and writes the resulting 1-D audio buffer with sf.write(...) at L270, so the documented output format contradicts actual behavior in that path.
The module docstring includes ecosystem-specific language such as 'P0/Oath/Guardian aware' and role/alignment references that present a particular operating framework as built in, without offering the user a choice or explaining a necessary locale/policy constraint. Because SQP-3 covers natural-language policy issues across all file types, this is a mild policy concern where the skill's framing could impose organizational conventions by default.
This code writes generated image output directly to disk, and elsewhere writes WAV/JSON outputs, but it provides no confirmation prompt and no user-facing warning in comments or docstrings about creating or potentially overwriting files at the chosen paths. For a code file, file writes are safety-relevant operations when there is no disclosure beyond generic CLI argument names.
No suspicious patterns detected.