Back to skill

Security audit

LYGO PC Lattice Hardening

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed advisory checklist for LYGO/Windows hardening and does not ship code that changes the system or accesses sensitive data.

Install this as advisory guidance, not as a complete hardening product. Run the optional stack audit only from a trusted LYGO_STACK_ROOT clone, review any recommendations yourself, and approve firewall, registry, publishing, or credential-related actions step by step.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
This is a mismatch because the declared purpose describes a Windows PC security auditing/hardening skill, but the provided code does not inspect or harden a PC, assess secrets, check security posture, or interact with ClawHub or Windows at all. Its primary function is merely to confirm that specific project files are present in the skill directory. That behavior is materially different from the claimed security-audit purpose.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description says "Use when user asks harden PC, lattice protected, super charge LYGO machine," which includes vague and colloquial phrases rather than a narrow trigger scope. These phrases are not constrained with exclusions or negative examples, increasing the chance of unintended invocation.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Items like "harden PC / lattice-protect the operator machine" and "Super-charge LYGO machine checklist" are not specific enough to distinguish this skill from general support or optimization requests. The file does not provide negative examples or narrow context constraints to prevent accidental matches.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.