Back to skill

Security audit

osc-bridge

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent guide for using osc-bridge to control music hardware and software, with its device-control risks disclosed and scoped to user-started local processes.

Install only if you intend to let an agent send OSC/MIDI/SysEx commands to your music software or hardware. Keep the bridge bound to localhost unless you deliberately need network access, verify MIDI output ports before sending, and treat raw SysEx as capable of changing device state.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.