Back to skill

Security audit

bridgenode

Security checks across malware telemetry and agentic risk

Overview

This skill clearly describes a paid third-party AI inference service and does not include hidden code, persistence, or unrelated access.

Install only if you are comfortable sending prompts to BridgeNode and allowing x402-capable clients to spend USDC per request. Use non-sensitive prompts unless third-party processing is acceptable, check the quoted 402 amount before signing where your client allows it, and configure wallet/spend controls outside the skill if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill routes user prompts to a third-party remote service and initiates a real on-chain USDC payment flow, but the description does not prominently warn users of either data disclosure or financial spend at the point of use. This can lead agents or operators to send sensitive prompt content off-platform and authorize unintended paid transactions without informed consent, especially in automated environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.