Back to skill

Security audit

LYGO Glyph2Resonance

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly performs local glyph-to-audio generation, but it automatically loads local integration modules and can write into a persistent memory system, so it should be reviewed before installation.

Install only in a controlled workspace. Treat any local lyra_brain.py or resonance_engine.py as trusted code before running, avoid processing attacker-supplied filenames if 3-Brain is present, and prefer pinned dependency and ClawHub tool versions. Review or disable the automatic memory-growth block if you want a purely local glyph-to-audio converter.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T07 · Tool Hijacking and Spoofing

Error
Location
glyph2resonance.py:367
Finding

Untrusted Local Module Loading Enables Arbitrary Code Execution

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
glyph2resonance.py:366
Finding

Automatic Persistent Memory Write Accepts Attacker-Controlled Filename Content

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:140
Finding

Unpinned Third-Party Installation and Publishing Commands Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
numpy== soundfile== ``` 2. Use a lockfile that captures transitive dependencies. 3. Require cryptographic hashes during installation, such as with: ```bash pip install --require-hashes -r requirements.txt ``` 4. Replace `npx clawhub@latest` with a fixed, reviewed package version. 5. Verify package signatures, provenance attestations, checksums, and registry ownership before installation. 6. Run installation and publishing operations in an isolated, least-privileged environment. 7. Avoid exposing publishing tokens to dependency installation steps. Load short-lived credentials only after tool verification and immediately before publication. 8. Document the exact reviewed dependency versions and establish a controlled process for updating them. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill is presented primarily as a local glyph-to-audio transformer, but the documentation also describes persistence to memory systems, queue/task integration, agent orchestration, and downstream profile generation beyond simple sonification. This mismatch is dangerous because users or agents may approve the skill expecting limited local processing while it performs broader ecosystem side effects, increasing the chance of unintended data retention, propagation, or automation.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
3. Copy the contents of this skill (`glyph2resonance.py`, `SKILL.md`, etc.) into it. If you have the lygo-resonance skill installed, copy or symlink its `resona

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill describes capabilities that write files locally, including WAV, JSON, MIDI, stems, generated images, and possible memory-growth artifacts, yet it declares no explicit tool scope or permissions. In agent ecosystems, missing scope declarations can cause overbroad execution assumptions and make file-writing side effects occur without clear user awareness or policy gating.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The documentation instructs users to run 'npx clawhub@latest publish ...', which pulls and executes the latest package version at runtime. This creates a supply-chain risk because a compromised or malicious upstream release could execute arbitrary code during publish operations, especially in environments where users copy commands directly from the skill.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill performs behavior beyond its declared sonification purpose by attempting to import a local module and persist derived content into a '3-Brain' memory system automatically. This creates an unexpected side effect on the host agent environment, and because it modifies external state using current working directory context, it can contaminate memory, create persistence, or interact with attacker-controlled local modules.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatic mutation of agent memory context is not necessary for image-to-audio conversion and violates least surprise. In an agent setting, silently appending generated summaries to memory can poison future reasoning, leak filenames/metadata into persistent context, and create cross-task influence without user approval.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

At L123 the documentation says outputs are 'local-first' and external use should be gated, implying a restrained/local workflow. Later lines L140-L143 provide direct ClawHub publishing steps, and earlier lines also promote external companion and donation URLs, which weakens that local-only framing and creates a mild intent/documentation inconsistency.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module documentation states 'Outputs: - Stereo WAV soundscape'. However, in the built-in synthesis path the code collapses the generated stereo layers to mono at L238 and writes the resulting 1-D audio buffer with sf.write(...) at L270, so the documented output format contradicts actual behavior in that path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
62% confidence
Finding

The module docstring includes ecosystem-specific language such as 'P0/Oath/Guardian aware' and role/alignment references that present a particular operating framework as built in, without offering the user a choice or explaining a necessary locale/policy constraint. Because SQP-3 covers natural-language policy issues across all file types, this is a mild policy concern where the skill's framing could impose organizational conventions by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code writes generated image output directly to disk, and elsewhere writes WAV/JSON outputs, but it provides no confirmation prompt and no user-facing warning in comments or docstrings about creating or potentially overwriting files at the chosen paths. For a code file, file writes are safety-relevant operations when there is no disclosure beyond generic CLI argument names.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.