Apow Mining
PassAudited by VirusTotal on May 15, 2026.
Findings (1)
The skill bundle facilitates autonomous cryptocurrency mining on the Base L2 network by wrapping the 'apow-cli' tool. It explicitly instructs the AI agent to generate a new Ethereum wallet, capture the plaintext private key from terminal output, and write it to a .env file (SKILL.md). While these actions are functionally necessary for the stated purpose, the handling of raw private keys by an AI agent and the execution of external code via 'npx' represent significant security risks. The documentation includes an extensive 'Security & Trust' section that attempts to preemptively address these concerns, but the high-risk nature of the operations and the potential for supply chain attacks via npm place this bundle in the suspicious category.
