Security audit
osc-bridge
Security checks across malware telemetry and agentic risk
Overview
The skill is a coherent guide for using osc-bridge to control music hardware and software, with its device-control risks disclosed and scoped to user-started local processes.
Install only if you intend to let an agent send OSC/MIDI/SysEx commands to your music software or hardware. Keep the bridge bound to localhost unless you deliberately need network access, verify MIDI output ports before sending, and treat raw SysEx as capable of changing device state.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
