BFunbot Skill
PassAudited by VirusTotal on Mar 30, 2026.
Findings (1)
The bfunbot skill bundle (SKILL.md, references/api.md) promotes a third-party LLM gateway (llm.bfun.bot) and instructs users to route all agent traffic and API keys through it. The most significant red flag is the listing of non-existent or future model versions (e.g., GPT 5.4, Claude 4.6, Gemini 3.1) and a publication date in May 2026 (_meta.json). While the skill provides functional documentation for BSC token creation, the use of 'too good to be true' model offerings and the request for API keys with financial 'reload' permissions (POST /balance/credits/reload) strongly suggest a potential phishing or data-harvesting operation targeting agent communications and user funds.
