Back to skill

Security audit

LYGO SkillSpector

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local static scanner; the scary-looking patterns are detector rules or test fixtures, not active malware.

Installers that use @latest should be pinned or independently verified in high-assurance environments. When running this scanner, scan only directories you intend to audit and do not paste or store reports publicly unless you have checked them for secrets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/skill_spector.py:270
Finding

Unredacted Secrets May Be Exposed Through Scan Reports

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:60
Finding

Installation Instructions Execute an Unpinned Latest Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/self_check.py (reported line 21)May include surrounding context.

python
lines = [
        "import subprocess",
        "import urllib.request",
        "subprocess.run(['echo','hi'], shell=True)",
        "urllib.request.urlopen('https://example.com')",
        f"api_key = {fake_proj!r}",
    ]

Chaining Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/skill_spector.py (reported line 9)May include surrounding context.

python
Pure stdlib. No network. No subprocess. No auto-install.

Detects:
  - network / urllib / requests / httpx / sockets / curl|bash
  - subprocess / os.system / shell / Popen / PowerShell IEX
  - secret-looking patterns (API keys, HF tokens)
  - permission claims vs code surface mismatch

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/skill_spector.py (reported line 133)May include surrounding context.

python
("password_literal", 4, re.compile(r"(?i)(password|api_key|secret)\s*=\s*['\"][^'\"]{8,}['\"]"), "Hardcoded credential-like string"),
    ("rm_rf", 4, re.compile(r"(?<![\"'])\bshutil\.rmtree\s*\("), "Destructive delete capability"),
    ("rm_rf_cmd", 5, re.compile(r"\brm\s+-rf\s+|Remove-Item\s+[^\n]*-Recurse\s+-Force"), "Recursive force delete command"),
    ("git_push", 3, re.compile(r"(?<![\"'])\bgit\s+push\b"), "git push capability"),
    ("force_push", 4, re.compile(r"git\s+push\s+[^\n]*--force|git\s+push\s+-f\b"), "Force-push capability"),
    ("curl_pipe", 5, re.compile(r"curl\s+[^|\n]*\|\s*(ba)?sh"), "curl|bash remote code pattern"),
    ("wget_pipe", 5, re.compile(r"wget\s+[^|\n]*\|\s*(ba)?sh"), "wget|bash remote code pattern"),

YARA rule 'keylogger_indicators': Keylogger functionality in scripts or source code [malware]

High
Category
YARA Match
Confidence
70% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/skill_spector.py (reported line 139)May include surrounding context.

python
code pattern"),
    ("wget_pipe", 5, re.compile(r"wget\s+[^|\n]*\|\s*(ba)?sh"), "wget|bash remote code pattern"),
    ("powershell_iex", 5, re.compile(r"(?i)\bIEX\s*\(|Invoke-Expression|DownloadString\s*\("), "PowerShell remote exec pattern"),
    ("clipboard", 2, re.compile(r"(?i)pyperclip|Set-Clipboard"), "Clipboard access"),
    ("keylogger_hint", 4, re.compile(r"(?i)pynput|keyboard\.Listener|GetAsyncKeyState"), "Keylogger-style input capture"),
    ("crypto_miner", 5, _RX_CRYPTO_MINER, "Crypto miner indicators (detection rule only)"),
    ("auto_install_pip", 3, re.compile(r"(?i)(?<!['\"])\bpip\s+install\b"), "pip install capability"),
    ("clawhub_publish", 3, re.compile(r"(?i)clawhub\s+publish|npx\s+clawhub.*publish"), "ClawHub publish capability"),
]

DOC_RULES: list[tuple[str, int, re.Pattern[str], str]] = [
    ("doc_auto_publish_enable", 2, re.compile(r"(?i)(enable|allows?|will)\s+auto[_-]?publish"), "Docs suggest enabling auto-publish"),
]

CODE_EXTS = {".py", ".ps1", ".sh

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The installation instruction uses npx clawhub@latest install ..., which does not pin an exact version of the package manager component. If the upstream clawhub package is compromised or a breaking/malicious release is published, users following the documented command could fetch and execute unreviewed code during installation. In the context of a security-focused scanning skill, this is more sensitive because users are likely to trust and run the recommended install path.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 12)May include surrounding context.

text
permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This Python file performs file writes via write_under_state(), and the scan/report commands also expose filesystem paths in output. Although writes require --i-consent, there is no docstring or inline user-facing disclosure near the write function itself explaining that reports will be persisted under the skill state directory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.