Nodit Openapi Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed, read-only Nodit Web3 API helper that sends user-supplied blockchain lookup data to Nodit using a scoped API key.

Use a dedicated Nodit API key with quota limits, expect blockchain identifiers you query to be sent to Nodit, and prefer the packaged or pinned OpenAPI schema if you need reproducible behavior instead of linking from a mutable GitHub main-branch URL.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The OpenAPI spec defines authenticated calls to a third-party service and supports sending account addresses and contract addresses, but the description shown to users does not clearly disclose that this data will be transmitted off-platform to Nodit. In an agent setting, users may provide wallet/account identifiers assuming local processing, so the lack of an explicit warning creates a meaningful privacy and data-sharing risk even though the endpoints are read-only.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal