Near Jsonrpc Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent read-only NEAR JSON-RPC helper with disclosed network use and no credential, wallet, destructive, or hidden behavior in the artifacts.

Install only if you are comfortable with uxc creating a local CLI link and sending read-only NEAR RPC requests to the configured provider. For stricter supply-chain control, use the bundled schema or a pinned schema URL instead of the moving GitHub main-branch URL, and keep use limited to the documented read-only methods.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
This is a mismatch because the declared purpose says the skill operates NEAR JSON-RPC reads through UXC, implying runtime behavior for interacting with a NEAR provider. The actual code shown does not perform any NEAR JSON-RPC calls, provider selection, or read-only request handling. Instead, it statically validates that certain files exist and contain expected strings and schema entries. That is a materially different primary purpose from the description.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal