Node of COC testnet

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed COC blockchain node-management helper with expected local disk, process, network, and removal controls.

Install this only if you intend to operate COC nodes. Verify the npm package and any COC repo path you configure, expect persistent local disk and network activity, and use --keep-data or a backup unless you intentionally want local node data removed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill documents a destructive command (`node remove NAME --yes`) that deletes node data, but it does not explicitly warn that this may irreversibly remove blockchain state, logs, and local configuration. In an operational skill that encourages lifecycle management, omission of a clear deletion warning increases the risk of accidental data loss, especially because `--yes` suppresses interactive confirmation.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal