Security audit
LYGO Mesh Deploy
Security checks for vulnerabilities and agentic risk
Overview
This skill is a transparent mesh-deployment helper whose network and script-running behavior is disclosed and aligned with its stated purpose.
Install appears acceptable for users who intend to test LYGO mesh deployment. Before running the cloned repository scripts, review them, run in an isolated workspace, avoid public exposure unless TLS and pin gossip are configured, and confirm any wide-area deployment manually.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
