Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add MingyiSecLab/Mingyi-Atlas --skill bridge-exploitgit clone --depth 1 https://github.com/MingyiSecLab/Mingyi-AtlasWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/bridge-exploit)<a href="https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/bridge-exploit"><img src="https://agentmods.dev/badge/skills/mingyiseclab/mingyi-atlas/bridge-exploit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/mingyiseclab/mingyi-atlas/bridge-exploit"><img src="https://agentmods.dev/badge/skills/mingyiseclab/mingyi-atlas/bridge-exploit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00062 | $0.01348 |
| Opus 5 | $0.00031 | $0.00674 |
| Sonnet 5 | $0.00012 | $0.00270 |
| Haiku 4.5 | $0.00006 | $0.00135 |
Grade A, and why
bridge-exploit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
98% identical to contracts-bridge-exploit — 2 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 115 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Cross-Chain Bridge Attack
Bridges hold large pooled assets and execute messages from a separate trust layer. Architecturally fragile.
Bridge taxonomy
| Type | Trust model | Past exploits |
|---|---|---|
| Lock-and-mint | Trusted validators sign mint events | Wormhole ($325M), Ronin ($600M), Harmony ($100M) |
| Burn-and-redeem | Same | Multichain/Anyswap ($126M) |
| Optimistic | Fraud proof window | Nomad ($190M) |
| Light-client / zk | Cryptographic | (Fewer hacks, but newer) |
| Liquidity-network (Hop, Connext) | Routers + relayers | Smaller individual exploits |
Attack classes
1. Validator-signature bypass (Wormhole, Feb 2022, $325M)
The Solana-side verify_signature function trusted the caller to provide a "verified" sigset account. Attacker passed a sysvar that wasn't a real sigset → unauthorized mint of 120k wETH.
Lesson: any verify function whose input is a struct fetched by address is bypassable if address-trust is missing.
2. Validator key compromise (Ronin, March 2022, $600M)
9-of-9 validators, 5 of which were operated by one entity. Sky Mavis got phished → attacker controlled 5 keys → arbitrary mint.
Lesson: validator decentralization isn't math, it's operational. Count distinct legal entities and key-storage methods, not just keys.
3. Merkle-proof forgery (Nomad, August 2022, $190M)
After an upgrade, the zero-hash was set as a "valid root" — any proof against root = 0 passed. The first attacker withdrew real funds; then thousands of others copy-pasted the same tx with their own address. ~$190M total.
Lesson: check initialize / upgrade scripts for accidental defaults — bytes32(0), address(0), 1 (often the most-tested value) becoming the trusted value.
4. Replay across chains (Multichain class)
Bridge tx signed for chain A is replayed on chain B because chainId wasn't bound into the signed message:
function claim(bytes32 nonce, uint256 amount, bytes calldata sig) external {
bytes32 hash = keccak256(abi.encode(nonce, msg.sender, amount)); // ⚠ no chainId
require(ecrecover(hash, ...) == validator);
token.transfer(msg.sender, amount);
}
// On chain A: legit claim
// On chain B (same validator, same token): replay the same sig
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 115 lines · 62 tokens per session scan A 19a0be071f92
bridge-exploit is a skill published in the GitHub repository MingyiSecLab/Mingyi-Atlas (11 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 62 tokens to every session and 1,348 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 98% identical to contracts-bridge-exploit, differing in 2 lines, and is treated as a copy.
Other skills, from other repositories
cis-aws-foundations-6.5
Ensure the default security group of every VPC restricts all traffic.
cis-aws-foundations-2.1.3
Ensure Organizations management account is not used for workloads.
cis-aws-foundations-2.12
Ensure access keys are rotated every 90 days or less.
cis-aws-foundations-2.5
Ensure MFA is enabled for the 'root' user account.
cis-aws-foundations-2.7
Eliminate use of the 'root' user for administrative and daily tasks.
cis-aws-foundations-4.4
Ensure that server access logging is enabled on the CloudTrail S3 bucket.