Chainbase OpenAPI Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed, read-only helper for querying Chainbase Web3 data, with the main user consideration being that queried wallet, token, and transaction identifiers are sent to Chainbase.

Install only if you are comfortable sending the wallet addresses, token contract addresses, and transaction hashes you query to Chainbase under your API key. Use a dedicated Chainbase key where practical, rotate it if needed, and consider using the bundled or pinned OpenAPI schema instead of the mutable GitHub main-branch URL.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The schema defines authenticated requests to an external API service but does not indicate any user-facing disclosure that wallet addresses, token contract addresses, and transaction hashes will be transmitted off-platform. In a Web3 context these identifiers may be sensitive from a privacy perspective, and silent exfiltration to a third-party provider can surprise users even when the queried data is publicly indexed on-chain.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal