Back to skill

Security audit

LYGO Ollama Army

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a local Ollama queue worker, but it has a real out-of-scope file write risk and uses an unpinned executable installer command.

Install only if you are comfortable with a local polling Ollama worker and local task/result files. Prefer a pinned clawhub installer version, do not pass untrusted values to queue_task.py --id, and treat the command-center task directory as an input channel that can trigger local Ollama processing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
queue_task.py:20
Finding

Unsanitized Task Identifier Permits Out-of-Scope File Writes

Content
View full analysis
Remediation
View remediation
Path: base = base.resolve() destination = (base / f"{task_id}.task.json").resolve() if destination.parent != base: raise ValueError("Task path escapes queue directory") return destination ``` 4. Use exclusive creation with mode `"x"` where overwriting existing tasks is unnecessary. 5. Apply restrictive directory and file permissions appropriate to the platform. 6. Add tests for absolute paths, `../` traversal, path separators, empty IDs, excessively long IDs, and duplicate IDs. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:50
Finding

Installation Executes a Mutable Unpinned npm Package

Content
View full analysis
Remediation
View remediation
install deepseekoracle/lygo-ollama-army ``` 2. Publish and document the expected npm package integrity hash or verified package provenance. 3. Use lockfiles and integrity-protected package resolution where installation tooling supports them. 4. Recommend inspecting or downloading the package without execution before running it in security-sensitive environments. 5. Document the trust boundary clearly: the npm installer is separate executable code and must be audited alongside the Skill. 6. Update pinned versions through an explicit review process rather than a mutable distribution tag. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented behavior does not fully match the described scope: additional roles, extra queue/result directories, and a polling daemon model expand the effective attack surface beyond what an operator may expect. This kind of mismatch is dangerous because users may grant trust or permissions based on incomplete documentation, leading to unintended processing paths or data exposure in extra filesystem locations.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx clawhub@latest pulls an unpinned package version at install time, which creates a supply-chain risk: a compromised or breaking future release could execute unintended code during installation. Even though the skill claims local-only behavior, the install path depends on retrieving and trusting the latest remote package version.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The daemon reads from and writes to additional command-center directories outside the declared ollama_queue path, which expands its trust boundary beyond what the skill advertises. If another local component can place task files in those directories, it can trigger processing through an undeclared channel, bypassing operator expectations and reducing auditability.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code's SAFE_ROLES allowlist includes roles beyond the skill metadata's declared local role set, such as "draft", "general", and "resonance-analyst". This creates a capability mismatch: operators or other components may trust the manifest's narrower scope while the daemon actually accepts broader task types, increasing the chance of unintended prompt handling or unauthorized workflow use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.