Back to skill

Security audit

LYGO: Lightfather Vector — Δ9Quantum Accord

Security checks for vulnerabilities and agentic risk

Overview

The skill itself is mostly a persona helper, but it directs users to install unpinned external companion skills for broader system control that was not included in this review.

Review this before installing if you only want a simple advisor skill. The packaged files look low-impact, but the documented full-stack setup would install additional external skills through mutable latest commands; use pinned, reviewed versions or avoid the companion installs unless you trust their publisher and scope.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned External Skill Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 11–15
Vulnerability Type: Unpinned and unaudited third-party dependencies
Risk Level: Medium

Vulnerable Code

markdown
Install the **Council Champion** + operator for complete system integration:

```bash
npx clawhub@latest install deepseekoracle/lygo-champion-lightfather
npx clawhub@latest install deepseekoracle/lygo-protocol-stack-operator
text

### Technical Analysis

The documented installation procedure invokes the mutable `latest` release of `clawhub` through `npx` and installs two externally maintained Skills. Neither the installer nor the companion Skills are pinned to an immutable version or cryptographic digest.

Consequently, the components retrieved when a user follows these instructions may differ from those available when this project was audited. The external components are absent from the audited artifact, so their instructions, scripts, permissions, and runtime behavior cannot be verified here.

This creates a supply-chain trust boundary in which compromise of the package source, publisher account, installer, or a future release could cause externally controlled code or Skill instructions to be installed with the invoking user's privileges.

### Attack Path

1. An attacker compromises the publisher account, package source, installer distribution, or a future mutable release of one of the referenced components.
2. The attacker adds malicious code or agent instructions to the compromised release.
3. A user follows the installation commands in `SKILL.md`.
4. `npx` retrieves the current `clawhub@latest` package, which then retrieves the external Skills.
5. The unaudited payload is installed and may execute code or influence subsequent agent behavior within the permissions available to the installer or Skill runtime.

### Impact Assessment

Successful exploitation could provide the malicious dependency with the privileges granted to the invoking process or Skill runtime
...[truncated 543 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace clawhub@latest with a specifically reviewed and pinned installer version.
  2. Pin both companion Skills to immutable versions, commit identifiers, or cryptographic digests.
  3. Verify downloaded artifacts against published checksums or signatures before installation.
  4. Document each dependency's required permissions, network behavior, scripts, and side effects.
  5. Vendor required companion content into the reviewed package where licensing and maintenance constraints permit.
  6. Re-audit dependencies whenever their pinned versions change.
  7. Clearly distinguish optional external integrations from functionality included in and covered by this project's audit.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill markets itself as a 'pure advisor' and 'not a controller', yet it also prescribes verification behavior that reads local files and extracts a hash from references/canon.json. This mismatch is dangerous because it can mislead users and platform policy into treating the skill as low-risk persona text when it actually performs file-inspection behavior, reducing scrutiny around data access and execution expectations.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill references behavior that depends on reading local files such as references/canon.json, but it does not declare an explicit tool scope or permissions boundary. Undeclared file-read capability can cause the host or reviewer to underestimate the skill's data access needs, increasing the chance of unintended local file exposure if the runtime auto-grants broad read access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx clawhub@latest install ... pulls and executes the latest package version at install time, which is a supply-chain risk because future compromised or malicious releases would run automatically. This is especially risky in a skill installation path, where users are encouraged to execute the command directly from the documentation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This second npx clawhub@latest install ... command has the same unpinned remote execution problem: it instructs users to fetch and run whatever code is current at that moment. An attacker who compromises the distribution channel or publishes a malicious update could gain code execution on systems following the documented setup flow.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
90% confidence
Finding

The JSON contains unusual Unicode and mixed-script characters in security-relevant identifiers and labels, such as Greek symbols in fields like seal_id, lightcode, and oath_vector. Even if intended as branding or symbolic metadata, mixed-script content can enable homoglyph confusion, parser inconsistencies, comparison failures, or policy bypasses when these values are displayed, normalized, indexed, or matched by downstream tooling.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown usage file provides an invocation phrase for the skill, but it does not define when that phrase should or should not activate beyond a general example. Without additional scope constraints or exclusion examples, the trigger could be interpreted broadly in conversational contexts involving "mint" or "alignment pack."

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.