Bitquery GraphQL Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Bitquery GraphQL helper, with credential-handling cautions users should manage carefully.

Install only if you trust your local `uxc` tool and need Bitquery API access. Use least-privileged Bitquery application credentials, avoid pasting real client secrets into shared terminals or logs, and monitor or stop live subscriptions so they do not consume API quota or grow local output files unexpectedly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation instructs users to supply an OAuth client secret directly on the command line but does not warn that command-line arguments can be exposed through shell history, process listings, logs, or terminal recordings. In a security-sensitive skill centered on authenticated API access, this omission can lead to credential disclosure and unauthorized use of the Bitquery account or associated data access.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal