Trust Assessment
bread-protocol received a trust score of 95/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include External Link for Wallet Connection Poses Credential Harvesting Risk.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 13, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | External Link for Wallet Connection Poses Credential Harvesting Risk The skill instructs users to connect their cryptocurrency wallet on an external website, `getbread.fun`. While this is a standard interaction pattern for decentralized applications (dApps), it introduces a potential risk of credential harvesting. If the external website were compromised, malicious, or a phishing site, users directed there by the AI agent could inadvertently expose their wallet's private keys or other sensitive information. The AI agent, by providing this instruction, acts as a conduit to this external risk. Verify the legitimacy and security of `getbread.fun` through independent means. Consider adding a prominent disclaimer to the user about the risks associated with connecting wallets to external sites. If possible, explore alternative interaction methods that do not require users to navigate to an external website for sensitive operations, or provide clear guidance on how users can verify the site's authenticity. | LLM | SKILL.md:15 |
Scan History
Embed Code
[](https://skillshield.io/report/3db304fb2ec1bfd9)
Powered by SkillShield