bnbchain
Security checks across malware telemetry and agentic risk
Overview
This is a disclosed BNB Chain MCP connector with sensitive wallet and transaction capabilities that are purpose-aligned but require careful use.
Install only if you intend to use BNB Chain MCP features. For read-only use, do not provide PRIVATE_KEY. For write actions, use a testnet or low-value wallet, verify the npm package or pin a version where possible, and confirm the network, recipient or contract, amount, approvals, and fees before any transaction.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
