Security audit
LYGO Network Builder
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed LYGO network verification helper that reads a configured stack, runs expected verification scripts, and probes public anchor URLs.
Install only if you intend to verify LYGO network anchors. Expect it to read the configured LYGO stack, run that stack's verification scripts, make HTTP GET checks to public anchor URLs, and write a local verification result file; do not use it with an untrusted LYGO_STACK_ROOT.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
