Botcoin Miner
PassAudited by VirusTotal on May 14, 2026.
Findings (1)
The skill automates a 'Proof-of-Inference' mining protocol on the Base network, requiring a sensitive BANKR_API_KEY to perform on-chain transactions including staking, swapping, and bridging. It is classified as suspicious because SKILL.md instructs the agent to treat external payloads from coordinator.agentmoney.net as 'authoritative' instructions, creating a significant prompt-injection surface that could be exploited to control the agent or misdirect funds if the remote coordinator is compromised. While the instructions include security disclaimers and the behavior aligns with the stated purpose, the combination of automated financial asset management and reliance on external logic execution presents a high-risk profile.
