Security audit
LYGO Lattice Pulse
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed plugin map and local integrity check with no hidden publishing, posting, credential use, or destructive behavior in the inspected artifacts.
Review the linked LYGO/OpenClaw plugin before installing because this package is mainly a skill map for that plugin; only set LYGO_STACK_ROOT to a local clone you trust and keep the documented human-consent step for any live chart write.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
