Back to skill

Security audit

LYGO RESONANCE | Image-to-Sound & Creative Profiles

Security checks for vulnerabilities and agentic risk

Overview

The creative image-to-sound tool is mostly coherent, but it includes broader publishing, token, memory, and mutable install guidance that users should review carefully.

Install and run this only in a dedicated project folder or virtual environment, preferably with pinned dependencies. Use local images/videos you intend to process, confirm before batch runs, and verify any LLM URL before sending briefs. Do not follow the ClawHub publishing, token-loading, memory-update, or external posting instructions unless you are intentionally maintaining/publishing this skill and have explicitly authorized those account or persistent-state changes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:72
Finding

Unpinned Third-Party Dependencies Create a Mutable Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:72, SKILL.md:82, and README.md:14
Vulnerability Type: Unpinned dependency installation
Risk Level: Medium

Vulnerable Code

SKILL.md:72:

text
**Dependencies (all modules):** `pip install opencv-python numpy soundfile mido gradio requests`

SKILL.md:82:

text
6. `pip install opencv-python numpy soundfile mido gradio requests`

README.md:14:

text
Install deps once: pip install opencv-python numpy soundfile mido gradio requests

Technical Analysis

The documented installation command retrieves the latest versions of six packages without version constraints or cryptographic hashes. Consequently, the dependency set installed by a user can differ from the dependency set reviewed during this audit.

These dependencies are necessary for the declared image, audio, MIDI, GUI, and LLM functionality. However, installing mutable releases directly from a package index exceeds the minimum supply-chain trust required. Python packages may run code during installation and are subsequently imported and executed by the project.

No evidence was found that the currently named packages are typosquatted or malicious. The vulnerability is the absence of controls ensuring that future installations receive known, reviewed artifacts.

Attack Path

  1. An upstream package release, maintainer account, distribution artifact, or configured Python package index is compromised.
  2. The attacker publishes a malicious version under one of the documented package names.
  3. A user follows the installation instructions without version or hash verification.
  4. pip resolves and installs the malicious release.
  5. Malicious installation hooks or imported package code execute with the privileges of the user running pip or the Skill.

Impact Assessment

Successful exploitation could execute arbitrary code with the installing user's privile ...[truncated 517 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create a reviewed lock file or requirements file containing exact dependency versions.
  2. Record cryptographic hashes and install with pip install --require-hashes -r requirements.txt.
  3. Separate direct dependencies from transitive dependencies while locking both.
  4. Install dependencies inside a dedicated virtual environment or restricted container rather than into the system Python environment.
  5. Add automated dependency scanning and controlled update review.
  6. Avoid recommending installation as root or administrator.
  7. Update SKILL.md and README.md so users install from the locked dependency manifest rather than using the unconstrained command.

T09 · Insecure Skill Coding Practices

Warning
Location
video_resonance_engine.py:45
Finding

Predictable Shared Temporary Files Allow File Clobbering and Cross-Run Interference

Content
View full analysis

Vulnerability Details

File Location: video_resonance_engine.py:45-46, video_resonance_engine.py:75, and video_resonance_engine.py:96-107
Vulnerability Type: Unsafe predictable temporary-file handling
Risk Level: Medium

Vulnerable Code

video_resonance_engine.py:45-46:

python
temp_img_path = "_temp_video_frame.jpg"
cv2.imwrite(temp_img_path, frames[-1])

video_resonance_engine.py:75:

python
cv2.imwrite(temp_img_path, frame)

video_resonance_engine.py:96-107:

python
engine.synthesize(seg_features, "_temp_seg.wav")
seg, _ = sf.read("_temp_seg.wav")

# Place in main audio
start_idx = int(i * sr / actual_fps)
end_idx = min(start_idx + len(seg), len(audio))
seg_len = end_idx - start_idx
audio[start_idx:end_idx] += seg[:seg_len]

# Cleanup
if Path("_temp_video_frame.jpg").exists():
    Path("_temp_video_frame.jpg").unlink()

The corresponding segment-file cleanup at video_resonance_engine.py:108-109 is:

python
if Path("_temp_seg.wav").exists():
    Path("_temp_seg.wav").unlink()

Technical Analysis

The video engine creates _temp_video_frame.jpg and _temp_seg.wav at fixed paths in the current working directory. The paths are shared by every invocation and are not created in a private per-process directory. There is no exclusive file creation, symlink validation, ownership check, or locking.

A local attacker with write access to the working directory can pre-create one of these paths or replace it during processing. Filesystem and codec operations may follow symbolic links or overwrite existing files. Concurrent legitimate runs can also overwrite one another's temporary data, causing one process to analyze or read data produced by another.

Cleanup is not placed in a finally block. If video analysis or synthesis raises an exception, temporary image or audio data can remain on disk.

Attack Path

A local file-clobb ...[truncated 1738 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create a private per-run directory with tempfile.TemporaryDirectory().
  2. Generate unpredictable paths inside that directory rather than using fixed names in the current working directory.
  3. Pass those generated paths consistently to OpenCV, the resonance engine, and SoundFile.
  4. Keep temporary-directory permissions restricted to the current user.
  5. Perform cleanup through the temporary-directory context manager or a try/finally block.
  6. Do not reuse temporary filenames across concurrent frame-processing operations.
  7. Where supported by the downstream library, avoid disk-backed temporary files entirely and process frame/audio data in memory.
  8. Run the engine in a non-shared, non-world-writable working directory and without elevated privileges.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description overstates the capabilities relative to this specific code chunk. The code does match part of the declaration: it performs computer-vision-based image analysis and produces structured creative JSON profiles plus an optional AI-ready brief, and it includes batch processing. However, the major advertised function of transforming images into stereo soundscapes/WAV is not present at all in this file. Likewise, there is no MIDI export, no Gradio interface, and no local LLM-based lyric expansion. The primary behavior of the code chunk is a profile/brief generator rather than a full image-to-sound suite. Because the declared description presents a substantially broader and materially different capability set than what this code actually implements, this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the agent to run local scripts, read and write files, launch a Gradio web UI, and communicate with a local HTTP LLM endpoint, but it does not declare any explicit tool scope or permission boundaries. That increases the chance an agent will use filesystem and network capabilities too broadly or without informed user consent, especially in automated environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises a local web UI and a local HTTP LLM integration but does not clearly warn that launching a server exposes an interface on the host and that prompts or content may be sent to another local service. Users may unknowingly expose sensitive images, briefs, or generated content to other processes or network-reachable interfaces depending on binding and local configuration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation guidance is broad and encourages direct execution, integration with multiple subsystems, memory writes, browser/network usage, and autonomous creative runs with only vague gating language. In agent settings, underspecified triggers and guardrails can cause overbroad actions on user files, local services, or publishing workflows without sufficiently explicit authorization.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

Referencing an 'npx variant' without pinning a specific package name and version creates a supply-chain risk because resolution may pull the latest published code at execution time. In an agent workflow, that can lead to unreviewed remote code being executed with local user privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

In batch mode, the function generates WAV/JSON and optional companion files for every image found and appends them for download, but there is no explicit warning or confirmation that this operation will create potentially many files on disk. For code files, file writes should have some user disclosure unless clearly warned elsewhere, and this file does not communicate the local write behavior beyond generic UI labels.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · llm_lyric_expander.py (reported line 41)May include surrounding context.

python
self._log(f"Contacting LLM at {self.llm_url} with model {self.model}...")
        
        try:
            response = requests.post(
                self.llm_url,
                json={
                    "model": self.model,

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Both the audio and profile paths create output files on disk, and optional MIDI, stem, and brief files may also be produced. Although the UI exposes downloadable outputs, the code lacks an explicit disclosure, prompt, or comment warning users that processing writes files locally and may generate additional companion artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code writes JSON output directly to the user-specified path and later writes a brief text file, but it does not warn or confirm before overwriting an existing file. Because these are filesystem-modifying operations, a minimal disclosure or overwrite warning would improve safety and prevent accidental data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill writes a .brief.txt file to disk as a side effect when --brief is enabled, but there is no user-facing warning that an existing brief file with the same name will be replaced. This is a file write operation lacking explicit disclosure at the point of action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code writes a temporary JPEG file to disk and later also writes a temporary WAV file during processing. Although there is a final success print and cleanup logic, there is no user-facing warning near the operation, no docstring for the method explaining that intermediate files are created, and no advance disclosure before these file writes occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The code writes the generated WAV output to the provided path, but only announces this after the write completes. Under this rule, file writes should have some visible disclosure such as a docstring, comment, or user-facing message explaining the action before it happens, unless already clearly documented elsewhere in the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.