ZetaChain Skill

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a disclosed, read-only blockchain analysis helper, with expected network queries and no clear evidence of hidden, destructive, or exfiltrating behavior.

Install only if you are comfortable with a globally installed npm CLI making live RPC requests to blockchain endpoints. Use explicit trusted RPC or Alchemy endpoints for reliability, avoid entering wallet private keys, and treat any balance or gas analysis as informational rather than financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill advertises executable commands that perform live blockchain queries, which implies network access, but the manifest does not declare any permissions. This creates a transparency and policy-enforcement gap: hosts or users cannot accurately assess what the skill is allowed to do, and undeclared network capability can bypass expected review or sandbox restrictions.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The static finding indicates the skill does more than its declared purpose by generating operational recommendations based on balances and gas prices and by querying multiple chain health metrics. That mismatch is dangerous because users may trust the skill as a passive information tool while it actually performs advisory logic that can influence financial actions, increasing the risk of misleading, manipulative, or unreviewed behavior.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal