Back to skill

Security audit

LYGO Immutable Anchor (Biophase7)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local receipt/hash tool that matches its stated no-network, no-auto-worker, consent-gated design.

This skill appears safe to install for local hashing and receipt generation. Do not put secrets in the truth, light, or note fields, and treat the documented protocol-stack worker command as a separate, higher-impact action that should be reviewed before running.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The quickstart instructs users to run an autonomy worker even though the skill metadata explicitly says the SLM/P7 worker is only planned and not spawned. This kind of documentation-to-manifest mismatch can mislead users into enabling unattended behavior they did not consent to, undermining the stated local-first and consent-gated security model.

Static analysis

No suspicious patterns detected.