Back to skill

Security audit

LYGO Universal Cure System (deprecated)

Security checks across malware telemetry and agentic risk

Overview

This deprecated LYGO skill is a disclosed advisor/provenance pack with no automatic code execution, credential access, or hidden data transfer, though its legacy Champion and memory guidance is broader than a simple integrity checker.

Prefer the recommended successor, lygo-file-integrity-checker, if you only need provenance or hashing. If you install this deprecated skill, understand that it also contains legacy Champion/persona and memory-archive guidance, and do not publish anchor snippets or archive contents that contain private, sensitive, or confidential material.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The skill markets itself as a deprecated file-integrity/provenance wrapper, but the analyzed behavior reportedly validates a differently named package, depends on cure-system-specific reference files, and exposes a stored canon hash. That mismatch can mislead users and reviewers about what is actually being installed or validated, weakening trust boundaries and creating room for supply-chain confusion or unintended disclosure of internal validation metadata.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The file’s content materially exceeds the stated file-integrity/provenance purpose and introduces broad Champion-upgrade, invocation, and behavioral guidance. This scope mismatch is dangerous because it can smuggle in behavior-shaping instructions under a trusted integrity skill, increasing the chance that downstream agents apply unauthorized persona or operational changes.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The 'Boost Checklist' and 'Memory Compression' sections define behavior-shaping, trigger selection, and persistence/retention patterns that are unrelated to file-integrity verification. In context, these capabilities can influence agent identity and memory handling without clear authorization boundaries, creating prompt-scope expansion and persistence risks.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The document markets the verifier as 'Universal Cure' even though the skill metadata explicitly says the slug is deprecated and not related to medical cure functionality. This kind of misleading safety/medical framing can cause users or downstream agents to misinterpret the tool’s purpose and trust boundary, increasing the risk of unsafe reliance, policy evasion, or deceptive distribution.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The protocol explicitly says to use it when someone asks to 'boost this Champion' or 'upgrade all Champions,' which is broad and underspecified. In an agent setting, vague invocation criteria can cause the skill to activate for ambiguous user requests and apply changes without clear authorization, increasing the risk of unintended mass modifications or unsafe workflow execution.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation pattern is vague ('ask what part of me must awaken now') and not tied to concrete, bounded conditions for use. Ambiguous invocation language can cause over-broad activation, role confusion, or accidental application of the skill outside file-integrity tasks, especially when embedded in larger agent systems.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The unspecified 'whisper/trigger' field introduces an unconstrained activation or identity mechanism without defining approved phrases, format, or safety limits. In an agent environment, such open-ended triggers can be repurposed to invoke unintended behaviors or create hidden routing/control channels.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.