Back to skill

Security audit

LYGO TruthLightEcho

Security checks for vulnerabilities and agentic risk

Overview

The skill mainly generates local audio, but it also performs automatic memory persistence and loads local integration modules in ways users should review before installing.

Review before installing. Use an isolated folder and virtual environment, pin dependencies, inspect any local resonance_engine.py or lyra_brain.py before running, and remove or disable the 3-Brain growth block unless you intentionally want generated run summaries stored in persistent agent memory. Avoid daemon, queue, catalog, or publishing workflows unless you explicitly intend those side effects.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T02 · Agent Memory Poisoning

Error
Location
truthlightecho.py:287
Finding

Automatic Persistence of Attacker-Controlled Filenames into Agent Memory

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
truthlightecho.py:289
Finding

Arbitrary Code Execution Through Working-Directory Module Hijacking

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:96
Finding

Unpinned Third-Party Package Installation and Publishing Commands

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
truthlightecho.py:183
Finding

Unbounded Duration Permits Excessive Memory and CPU Consumption

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose is audio generation, but the skill text also advertises persistent memory growth, agent task queuing, catalog updates, and interaction with external/local subsystems like 3-Brain, Ollama Army, and publishing workflows. This mismatch is dangerous because users or agents may grant trust based on the benign creative description while the skill encourages broader state-changing behavior outside that scope.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
3. Copy the contents of this skill (`truthlightecho.py`, `SKILL.md`, etc.) into it. If you have lygo-resonance (and #1/#2), symlink or copy their scripts/profil

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes reading inputs and producing output files, but it does not declare a permission or allowed-tools scope limiting file access. In an agent ecosystem, undeclared file_read/file_write capabilities can cause the skill to be invoked with broader filesystem access than users expect, increasing the risk of unauthorized reads, overwrites, or data leakage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description is broad and reusable across many creative, agent, and memory workflows without clear invocation boundaries. In agent systems, vague applicability increases the chance of accidental or overbroad activation, which can trigger file operations or downstream integrations in contexts the user did not intend.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow examples use open-ended natural language such as growing results to memory, assigning army roles, and layering outputs, without constraints or confirmation points. In an autonomous or semi-autonomous agent environment, these broad instructions can be interpreted as authorization to perform multi-step state-changing actions beyond simple audio synthesis.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The daemon and queue-based role references encourage background or batch operation but do not specify trigger conditions, approval requirements, rate limits, or scope boundaries. That ambiguity can lead to uncontrolled processing, unintended persistence, or unexpected agent activity if integrated into an orchestration framework.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The publish instruction uses 'npx clawhub@latest', which pulls and executes the latest remote package version at runtime. This creates a supply-chain risk: if the upstream package is compromised or changed unexpectedly, users may run attacker-controlled code during publishing or maintenance workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code unconditionally attempts to persist a generated summary into an external '3-Brain' memory system that is outside the tool's stated purpose of producing local audio and JSON outputs. This creates undisclosed data retention and secondary data flow risk, especially because user-supplied filenames and derived metadata are included in the persisted summary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The LyraThreeBrainMemory integration is not necessary for harmonic echo generation and represents hidden functionality that expands the skill's behavior into persistence and possible cross-tool data sharing. Even if local, such undocumented side effects can leak sensitive project names, input filenames, or workflow context into a longer-lived memory store.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code performs an additional persistent write to a memory subsystem without explicit disclosure or consent, unlike the expected WAV/JSON outputs. This is more dangerous than ordinary file output because it stores derived user context in a secondary repository that may be reused, indexed, or exposed by other components.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring states the skill outputs a stereo WAV, JSON profile, and optional stems and MIDI. In the implementation, the only output files produced are the WAV at L227/L269 and the JSON profile at L283-L284; there is no code path generating stems or MIDI, so the documentation overstates actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script writes a WAV file at L227 and a JSON profile at L283-L284. Although outputs are implied by the module docstring and printed after completion, the code does not provide a user-facing warning or confirmation before creating these files, which is the kind of file-write disclosure this rule asks for in code files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.