Back to skill

Security audit

NEXUS Mcp Bridge

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed paid network bridge to a third-party NEXUS API, with no artifact evidence of hidden local file access, shell execution, persistence, or deception.

Install only if you trust NEXUS with the prompts you send and with payment proof verification. Do not include secrets, private repository contents, or sensitive filesystem data in requests unless that is intentional, and prefer sandbox or tightly scoped payment credentials for testing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described as a bridge to IPFS, GitHub, and the filesystem but provides no warning that prompts, files, repository data, or other sensitive content may be transmitted or that local system state may be affected. In this context, missing privacy and system-impact disclosures materially increase the risk of users enabling a powerful connector without informed consent.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 16)May include surrounding context.

Or manually copy the SKILL.md to your OpenClaw skills directory:

bash
cp SKILL.md ~/.openclaw/skills/nexus-mcp-bridge/SKILL.md

Usage

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states the skill is 'automatically invoked' for 'matching tasks' without defining the trigger scope, data shared, or approval boundaries. For a bridge that can connect to external MCP servers including GitHub and the filesystem, vague activation criteria can cause unintended invocation and unexpected data exposure or side effects.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The documented usage sends arbitrary user input to an external hosted service, which is an external transmission channel. In a bridge skill context, this is expected behavior, but it is still security-relevant because sensitive prompts or file-derived content could be sent off-device to a third party without clear minimization or warning.

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

bash
# Step 1: Get the x402/MPP challenge
curl -X POST https://ai-service-hub-15.emergent.host/api/original-services/mcp-bridge \
  -H "Content-Type: application/json" \
  -d '{"input": "your query here"}'
# Returns 402 + WWW-Authenticate: Payment header

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill explicitly instructs the agent to transmit user-provided input and a payment proof token to an external third-party endpoint. Even though this is the advertised purpose of the skill, it still creates a real data-exfiltration and secret-exposure risk because the request sends potentially sensitive prompts off-platform and includes an environment-derived credential in a header.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

API Call

bash
curl -X POST https://ai-service-hub-15.emergent.host/api/original-services/mcp-bridge \
  -H "Content-Type: application/json" \
  -H "X-Payment-Proof: $NEXUS_PAYMENT_PROOF" \
  -d '{

Static analysis

No suspicious patterns detected.