Back to skill

Security audit

LYGO Kickstart Wizard

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed onboarding helper that performs local guidance, optional fixed-endpoint health checks, and user-directed file hashing or text analysis without hidden publishing or persistence.

Before installing, note that the lattice command makes HTTPS GET requests to fixed public endpoints, analyze may import a locally installed lygo-ops-detector, and --text-file, --pack, or --write operate on paths you provide. Avoid feeding private third-party text unless you have authority, and use --write only for locations you intend to create or overwrite.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
78% confidence
Finding
The skill includes very broad natural-language prompts such as 'Where do I start?' and 'Which skill do I need?' that could overlap with ordinary user conversation and unintentionally trigger the skill in systems that route by semantic matching. In an agent ecosystem, accidental invocation can cause confusing behavior, unnecessary network requests, or unintended access to user-provided files if the workflow continues from the wrong tool.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.