Back to skill

Security audit

LYGO Living Mesh (Layer D)

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local mesh-verification and badge-gossip helper with consent controls and no evidence of hidden publishing, credential use, or destructive behavior.

Install only if you intend to use the LYGO protocol stack and are comfortable with local Python tools reading/writing LYGO stack status files and optionally contacting peer HTTP endpoints. Do not set LYGO_STACK_ROOT to an untrusted directory, and only run join or gossip commands for peers you explicitly choose.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill documentation instructs the agent to use shell commands and environment variables such as exporting LYGO_STACK_ROOT and running multiple Python scripts, but it does not declare corresponding permissions. This creates a mismatch between the skill’s stated security posture and its actual capabilities, which can lead to unexpected command execution or environment access if the hosting platform relies on declared permissions for policy enforcement.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.