Back to skill

Security audit

LYGO Kernel Egg Planter

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly transparent about running user-selected LYGO stack tools, but it has consent and safety-check mismatches that users should review before installing.

Install only if you control and trust the LYGO_STACK_ROOT repository, prefer --local-only, avoid smoke_test.py unless you are comfortable with it listing registry contents, and do not use optional external anchoring for anything that could contain private or secret data.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/smoke_test.py:21
Finding

Smoke Test Bypasses the Explicit Retrieval Consent Requirement

Content
View full analysis
int: ap = argparse.ArgumentParser() ap.add_argument("--stack-root", default=None) args = ap.parse_args() root_args = ["--stack-root", args.stack_root] if args.stack_root else [] steps = [ ("preflight.py", root_args), ("verify_eggs.py", root_args), # list requires consent after v1.3 SkillSpector harden ("retrieve_egg.py", ["--i-consent", "--list", *root_args]), ] for name, extra in steps: rc = run(name, extra) if rc != 0: print(f"smoke_test FAIL at {name} (exit {rc})", file=sys.stderr) return rc print("smoke_test: PASS") return 0 ``` ### Technical Analysis The retrieval wrapper requires affirmative user consent before listing or retrieving egg registry content. However, the smoke test unconditionally supplies `--i-consent` to `retrieve_egg.py` on the user's behalf. This is inconsistent with the consent model implemented in `scripts/_stack_paths.py`, under which consent must come from an explicit command-line flag or the `LYGO_EGG_PLANT_CONSENT` environment variable. It also contradicts the documented requirement that consent must never be inferred. Although `retrieve_egg.py` performs verification before access, integrity verification and authorization are separate controls. Successful verification does not establish that the user consented to registry access. The smoke test therefore converts an ordinary smoke-test invocation into an authorized retrieval-list operation without requiring the caller to provide the authorization signal. ### Attack Path 1. A valid LYGO stack is configured through `--stack-root`, `LYGO_STACK_ROOT`, or automatic stack-root discovery. 2. The user runs: ```bash python scripts/smoke_test.py ``` without ...[truncated 1154 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/preflight.py:26
Finding

Preflight Secret Detection Does Not Enforce Its Security Policy

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Again, the risk is misleading security posture: the skill describes planting, verification, and retrieval controls, but the visible artifact appears to emit references and delegate work elsewhere. In security-sensitive tooling, this mismatch can directly lead to unsafe operational decisions and bypass of expected integrity checks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Again, the risk is misleading security posture: the skill describes planting, verification, and retrieval controls, but the visible artifact appears to emit references and delegate work elsewhere. In security-sensitive tooling, this mismatch can directly lead to unsafe operational decisions and bypass of expected integrity checks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Again, the risk is misleading security posture: the skill describes planting, verification, and retrieval controls, but the visible artifact appears to emit references and delegate work elsewhere. In security-sensitive tooling, this mismatch can directly lead to unsafe operational decisions and bypass of expected integrity checks.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill invokes shell commands, reads environment variables, and operates on local files, but the file itself does not declare an enforceable tool scope in the analyzed artifact. That weakens policy enforcement and makes it easier for an agent runtime to grant broader capabilities than intended, especially because the skill delegates execution to external scripts under a trusted path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx clawhub@latest install ... pulls and executes the latest package version at install time, which creates a supply-chain risk and makes builds non-reproducible. If the upstream package is compromised or changes behavior, users may execute malicious code before any of the skill's consent or verification safeguards apply.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/CONSENT_AND_ETHICS.md (reported line 7)May include surrounding context.

md
## User rights

- **Opt-in only.** No background planting, no “helpful” auto-anchor without approval.
- **Transparent payloads.** Eggs are JSON manifests + optional inline **public** source from the LYGO stack. No env vars, API keys, or Discord tokens are read or embedded.
- **Revocation.** Local eggs can be deleted from `data/anchors/`; permaweb is immutable by design — do not plant secrets.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

md
|---------|----------|-----|
| Manifest undeclared permissions | Medium | `claw.json` permissions block |
| "no auto-publish" vs surfaces | Medium | Core planter docs; pages/clawhub redirect text |
| Retrieve without consent | Medium | `--i-consent` required on retrieve |
| `--skip-verify` / `--force` | High | **Removed** |
| Catalog MultiAnchor auto | High | `plant_clawhub_catalog.py` local by default; `--anchor-external` opt-in |
| Champions/stubs scope creep | Medium | Removed from core planter; dedicated scripts only |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/AGENT_CONTRACT.md (reported line 36)May include surrounding context.

md
|---------|----------|-----|
| Manifest undeclared permissions | Medium | `claw.json` permissions block |
| "no auto-publish" vs surfaces | Medium | Core planter docs; pages/clawhub redirect text |
| Retrieve without consent | Medium | `--i-consent` required on retrieve |
| `--skip-verify` / `--force` | High | **Removed** |
| Catalog MultiAnchor auto | High | `plant_clawhub_catalog.py` local by default; `--anchor-external` opt-in |
| Champions/stubs scope creep | Medium | Removed from core planter; dedicated scripts only |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/AGENT_CONTRACT.md (reported line 37)May include surrounding context.

md
|---------|----------|-----|
| Manifest undeclared permissions | Medium | `claw.json` permissions block |
| "no auto-publish" vs surfaces | Medium | Core planter docs; pages/clawhub redirect text |
| Retrieve without consent | Medium | `--i-consent` required on retrieve |
| `--skip-verify` / `--force` | High | **Removed** |
| Catalog MultiAnchor auto | High | `plant_clawhub_catalog.py` local by default; `--anchor-external` opt-in |
| Champions/stubs scope creep | Medium | Removed from core planter; dedicated scripts only |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/SKILLSPECTOR_AUDIT.md (reported line 12)May include surrounding context.

md
|---------|----------|-----|
| Manifest undeclared permissions | Medium | `claw.json` permissions block |
| "no auto-publish" vs surfaces | Medium | Core planter docs; pages/clawhub redirect text |
| Retrieve without consent | Medium | `--i-consent` required on retrieve |
| `--skip-verify` / `--force` | High | **Removed** |
| Catalog MultiAnchor auto | High | `plant_clawhub_catalog.py` local by default; `--anchor-external` opt-in |
| Champions/stubs scope creep | Medium | Removed from core planter; dedicated scripts only |

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script advertises a consent-gated planting flow but forwards a '--skip-army' option to the downstream planter, creating a built-in bypass of part of the expected guarded process. Given the metadata claim of mandatory no-skip post-plant verification, exposing an operator-accessible skip path can undermine integrity checks and allow incomplete or unverified planting to proceed.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/plant_champion_council.py (reported line 27)May include surrounding context.

python
cmd = [sys.executable, str(stack / "tools" / "champion_egg_planter.py"), "--i-consent"]
    if args.skip_army:
        cmd.append("--skip-army")
    return subprocess.call(cmd, cwd=stack)


if __name__ == "__main__":

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/retrieve_egg.py (reported line 61)May include surrounding context.

python
cmd = [sys.executable, str(stack / "tools" / "champion_egg_planter.py"), "--i-consent"]
    if args.skip_army:
        cmd.append("--skip-army")
    return subprocess.call(cmd, cwd=stack)


if __name__ == "__main__":

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/plant_with_consent.py (reported line 29)May include surrounding context.

python
def run_verify(stack: Path) -> int:
    return subprocess.call(
        [sys.executable, str(SCRIPT_DIR / "verify_eggs.py"), "--stack-root", str(stack)]
    )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
89% confidence
Finding

This code executes a Python script located under a user-supplied or environment-resolved stack root, and the program explicitly acknowledges that the stack is executable trust. Although the basename is allowlisted, an attacker who can influence LYGO_STACK_ROOT or the provided stack directory can place malicious build/anchor/retrieve scripts in stack/tools and obtain arbitrary code execution when this wrapper runs them.

Content

Scanner excerpt · scripts/plant_with_consent.py (reported line 46)May include surrounding context.

python
cmd = [sys.executable, str(tool)]
    if extra:
        cmd.extend(extra)
    subprocess.check_call(cmd, cwd=stack)


def main() -> int:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/plant_with_consent.py (reported line 88)May include surrounding context.

python
return 2

    stack = resolve_stack_root(args.stack_root)
    subprocess.check_call([sys.executable, str(SCRIPT_DIR / "preflight.py"), "--stack-root", str(stack)])

    surfaces = {s.strip().lower() for s in args.surfaces.split(",") if s.strip()}
    # Redirect expanded surfaces — keep function via separate scripts, not silent expansion

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/retrieve_egg.py (reported line 45)May include surrounding context.

python
return 1

    # Always verify first — no bypass
    rc = subprocess.call(
        [sys.executable, str(SCRIPT_DIR / "verify_eggs.py"), "--stack-root", str(stack)]
    )
    if rc != 0:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/smoke_test.py (reported line 18)May include surrounding context.

python
cmd = [sys.executable, str(SCRIPT_DIR / script)]
    if extra:
        cmd.extend(extra)
    return subprocess.call(cmd)


def main() -> int:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/verify_all_layers.py (reported line 21)May include surrounding context.

python
)
        return 1
    extra = sys.argv[1:]
    return subprocess.call([sys.executable, str(tool), *extra], cwd=str(stack))


if __name__ == "__main__":

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/verify_eggs.py (reported line 22)May include surrounding context.

python
stack = resolve_stack_root(args.stack_root)
    tool = stack / "tools" / "verify_kernel_eggs.py"
    rc = subprocess.call([sys.executable, str(tool)], cwd=stack)
    out = stack / "tests" / "kernel_eggs_last_run.json"
    if args.json and out.is_file():
        print(out.read_text(encoding="utf-8"))

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 12)May include surrounding context.

text
permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE

Static analysis

No suspicious patterns detected.