Back to skill

Security audit

mempool.space Public API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed read-only helper for querying public mempool.space Bitcoin and Lightning API data, with no evidence of hidden or destructive behavior.

Install this if you are comfortable with a UXC-created local command that sends queried addresses, transaction IDs, Lightning public keys, and search terms to mempool.space. For automated or sensitive workflows, consider verifying or pinning the referenced OpenAPI schema instead of relying on the GitHub main-branch URL.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.