Security audit
bitfence
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed, read-only token risk-checking helper, with clear user consent requirements for paid API calls and optional contextual data sharing.
Before installing, understand that each risk check may spend a small amount of USDC on Base and sends token identifiers to Bitfence; contextual checks may also send position size and total portfolio size only if you opt in. Treat the result as advisory, not a guarantee of safety.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
