Back to skill

Security audit

LYGO Universal Cure System (deprecated)

Security checks for vulnerabilities and agentic risk

Overview

This deprecated skill is not malicious, but its file-integrity framing is mixed with broad persona, memory, public-anchoring, and unpinned installer instructions that need review before installation.

Review this as a legacy/deprecated package, not a narrow integrity checker. Install the successor only through a pinned and trusted installer if possible, and do not let the Champion, memory archive, or public anchor workflows run unless you explicitly want those persona/provenance behaviors.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Execution of an Unpinned Third-Party Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:9
Vulnerability Type: Insecure third-party dependency execution
Risk Level: Medium

Vulnerable Code

markdown
> **Install instead:** `npx clawhub@latest install deepseekoracle/lygo-file-integrity-checker`

Technical Analysis

The installation instruction invokes npx with the mutable latest tag. This causes the package manager to retrieve and execute a release of clawhub that was not included in the audited project. Neither a fixed package version nor an integrity digest constrains the code that will run.

Consequently, the effective installer can change after this Skill has been reviewed. If the package registry, maintainer account, package publication process, or a future release is compromised, following the documented instruction could execute attacker-controlled package code.

The audited project itself does not contain malicious executable code. This finding concerns the supply-chain boundary created by the installation instruction.

Attack Path

  1. An attacker compromises the package publisher, registry distribution path, or release process for the referenced npm package.
  2. The attacker publishes a malicious release that resolves under clawhub@latest.
  3. A user follows the installation instruction in SKILL.md.
  4. npx downloads and executes the malicious package release.
  5. The package runs with the permissions of the invoking user and may also install unreviewed Skill content.

Impact Assessment

Successful exploitation could execute arbitrary code within the invoking user's privilege boundary. Depending on that user's permissions and environment, the malicious package could read or modify accessible files, access environment variables and credentials available to the process, make network requests, or install additional untrusted content.

The project provides no evidence that the current external package is malicious, and no privilege escalation beyond the ...[truncated 55 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace clawhub@latest with an explicitly reviewed and immutable package version.
  2. Pin and verify the package using a trusted registry-provided integrity digest or an independently published cryptographic checksum.
  3. Document the expected package publisher and trusted registry so users can validate provenance before execution.
  4. Review the pinned package, its transitive dependencies, and installation lifecycle scripts.
  5. Prefer a lockfile-backed installation process using integrity metadata where practical.
  6. Avoid automatically executing remotely retrieved package code; provide a download-and-verify workflow before installation when possible.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill presents conflicting identity signals: the slug and title use 'Universal Cure System' while the description claims it is only a deprecated file-integrity/provenance package and not a medical cure. This kind of description-behavior mismatch can mislead users and automated systems about the skill's true purpose, increasing the chance of unsafe installation, incorrect trust decisions, or hidden functionality escaping scrutiny.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx clawhub@latest install ... relies on a moving, unpinned package version at install time. If the upstream package is compromised or a breaking change is introduced, users of this deprecated skill could execute unintended code during installation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The phrase “boost this Champion” or “upgrade all Champions” is broad enough that it could be triggered by ordinary user requests rather than an explicit administrative or maintenance intent. In an agent skill, ambiguous invocation language can cause unintended execution paths, especially when the skill performs packaging, anchoring, or upgrade-related actions that may alter state or provenance records.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document branding and framing repeatedly describe a broad 'Universal Cure System' and universal upgrade mechanism, while the skill metadata says this deprecated slug is only for file-integrity/provenance. That mismatch can mislead users or downstream agents into applying the skill outside its intended safety boundary, increasing the chance of inappropriate reliance, scope creep, and unsafe persona-transfer behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The 'Mirror Summoning Protocol' presents an activation sequence using ritualized language such as treating a seal as a portal and asking what part must awaken. Even if metaphorical, ambiguous invocation patterns can cause unintended triggering, user confusion, or downstream agent misinterpretation, especially in ecosystems that map natural-language phrases to actions or modes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This section instructs the system to 'boost' any Champion by defining identity anchors, behavior contracts, triggers, memory compression, and upgrade add-ons, which goes well beyond provenance verification. In a skill that should only address integrity and tamper evidence, these generalized persona/behavior modification instructions create capability expansion and can be repurposed to alter agent behavior without clear authorization or review.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation labels the verifier as a "Universal Cure," which directly conflicts with the skill metadata stating it is only for file-integrity/provenance and not a medical cure. This kind of misleading framing can cause users or downstream agents to misuse the skill, trust it for inappropriate purposes, or propagate unsafe claims, especially in ecosystems where documentation is treated as operational guidance.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage instructions promote using the verifier to mint persona packs, upgrade packs, summon prompts, workflows, and master archives, which expands the apparent scope beyond integrity/provenance checking. This is dangerous because it can mislead users into treating the verifier as an authorization or packaging mechanism for arbitrary artifacts, increasing the chance of unsafe trust decisions and supply-chain style misuse.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring presents the component as a 'Universal Cure System' even though the code only validates local files and references. This misleading framing can cause users or downstream agents to overtrust the skill's purpose and safety properties, especially in contexts where medical or safety-critical claims would materially affect behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.