Back to skill

Security audit

LYGO Public Lattice Gate

Security checks across malware telemetry and agentic risk

Overview

The skill’s behavior is limited and purpose-aligned, but its license text is inconsistent and should be clarified before reuse.

This appears safe to install for its stated public verification and dry-run proposal workflow. Before redistributing or relying on reuse rights, ask the publisher to resolve the conflicting license statements; also review the fixed public domains it contacts and only use optional write flags with paths you intend to create or overwrite.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
78% confidence
Finding
The file contains contradictory license statements: frontmatter declares MIT-0 while the body says the license is LYGO Sovereign License v2.0 and explicitly 'not MIT.' This inconsistency can mislead users about reuse rights, redistribution, and trust boundaries, and it may be exploited socially to induce installation or reuse under false assumptions. While not a code-execution issue, it is a supply-chain and governance risk because security review and adoption decisions often rely on accurate metadata.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.