Back to skill

Security audit

Bittensor AI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly disclosed Bittensor AI integration that sends requests to an external gateway and may spend USDC per call, with no packaged executable code or hidden persistence found.

Install only if you are comfortable sending prompts, documents, and image requests to the Spraay gateway and Bittensor miners, and use a dedicated low-balance wallet because calls can spend real USDC. Do not send sensitive or proprietary content unless that external processing is acceptable.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.