Back to skill

Security audit

Bonero-Miner

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly about installing and running a cryptocurrency miner, but its quick install path executes a mutable remote script with broad local authority.

Review this skill carefully before installing. The mining behavior is disclosed, but do not run the quick install command unless you trust the upstream repository at execution time; prefer pinned source, checksums or signatures, a disposable build environment, and an unprivileged account. Only mine with explicit human approval and on hardware where CPU, power, network use, and privacy-coin activity are acceptable.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:33
Finding

Unverified Remote Installer Download and Shell Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 33–40
Vulnerability Type: Remote payload retrieval and execution through a mutable, unverified dependency
Risk Level: Critical

Vulnerable Code:

bash
curl -fsSL https://raw.githubusercontent.com/happybigmtn/bonero/master/install.sh | bash

The alternative installation procedure is also unpinned and lacks integrity verification:

bash
curl -fsSLO https://raw.githubusercontent.com/happybigmtn/bonero/master/install.sh
less install.sh  # inspect it
bash install.sh --add-path

Technical Analysis

The recommended quick-install command retrieves install.sh from the mutable master branch of an external personal GitHub repository and streams it directly into bash. The effective code executed by users can therefore change after the Skill has been reviewed.

The project artifact contains only SKILL.md; it does not include the installer itself. Consequently, the installer's behavior, filesystem changes, subprocesses, downloaded dependencies, and effective privilege requirements cannot be audited from the submitted artifact.

No commit hash, versioned release, cryptographic checksum, or digital signature is used to establish the integrity or identity of the downloaded script. HTTPS protects the connection in transit but does not protect against repository compromise, maintainer-account compromise, or later modification of the master branch.

The alternative procedure allows manual inspection but does not enforce it or cryptographically bind the inspected file to an approved version. It ultimately executes the same mutable remote script. Remote source retrieval is relevant to installing the declared miner, but direct execution of mutable content is not necessary and exceeds the minimum safe trust boundary for that functionality.

This finding does not establish that the remote script is currently malicious. The vulnerability is the unver ...[truncated 1806 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | bash installation command entirely.
  2. Include the installer in the Skill package so its complete behavior can be reviewed together with the documentation.
  3. If remote distribution is required, use a versioned release artifact rather than the mutable master branch.
  4. Pin the source to a reviewed commit hash and pin every recursive submodule to a reviewed commit.
  5. Publish an expected SHA-256 or stronger digest through a separately protected release channel and verify it before execution.
  6. Prefer signed release artifacts and verify the signature against a documented, trusted maintainer key.
  7. Download the installer to a local file, display it for review, and require explicit human authorization before execution.
  8. Fail closed when checksum or signature verification fails; do not provide an option that silently bypasses verification.
  9. Run installation and mining under a dedicated, unprivileged account. Avoid sudo unless a specific operation demonstrably requires it.
  10. Document all expected filesystem modifications, PATH changes, network endpoints, subprocesses, and downloaded dependencies.
  11. Provide an uninstall procedure that removes installed binaries and reverses configuration changes.
  12. Use reproducible build instructions where feasible so users can verify that binaries correspond to the pinned source.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The command chains network retrieval directly into shell execution with '| bash', which is dangerous because it gives remote content immediate code execution. This pattern is especially problematic in an agent skill, where automated systems may execute commands without human scrutiny. Given the skill's purpose is mining a privacy coin, the surrounding context raises the risk of misuse, stealthy persistence, and unauthorized consumption of CPU resources.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

Quick Install

bash
curl -fsSL https://raw.githubusercontent.com/happybigmtn/bonero/master/install.sh | bash

Or verify first:

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The skill instructs the user to download and execute an external install script from GitHub. Even though it suggests inspecting the file first, it still normalizes running unaudited remote code that can change over time or be replaced if the upstream repo is compromised. In the context of a cryptocurrency mining skill, this is more dangerous because the fetched script could silently install persistence, alter PATH, or deploy unwanted miners or backdoors.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

Or verify first:

bash
curl -fsSLO https://raw.githubusercontent.com/happybigmtn/bonero/master/install.sh
less install.sh  # inspect it
bash install.sh --add-path

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
71% confidence
Finding

The documentation tells the user to run package installation with sudo, which elevates privilege and can change the host system. While common for dependency setup, privilege escalation is still security-relevant because it increases the blast radius if the command is modified, copied into a larger unsafe sequence, or executed on a sensitive machine. In a mining-related skill, encouraging privileged setup deserves extra scrutiny because miners are often abused for unauthorized resource use.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

bash
# Dependencies (Ubuntu/Debian)
sudo apt-get install -y build-essential cmake pkg-config \
    libboost-all-dev libssl-dev libzmq3-dev libunbound-dev \
    libsodium-dev libhidapi-dev liblzma-dev libreadline-dev

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
pgrep bonerod && echo "running" || echo "stopped"

# Get blockchain height
curl -s http://127.0.0.1:18081/json_rpc \
    -d '{"jsonrpc":"2.0","id":"0","method":"get_info"}' | jq '.result.height'

# Check wallet balance

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

Piping a script fetched over the network directly into bash is a classic unsafe installation pattern. It removes any meaningful review step and allows immediate execution of attacker-controlled code if the source repository, network path, or hosting account is compromised. In a cryptocurrency miner skill, this is especially risky because hidden payloads could install persistence, exfiltrate wallets, or deploy unauthorized mining software.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

Quick Install

bash
curl -fsSL https://raw.githubusercontent.com/happybigmtn/bonero/master/install.sh | bash

Or verify first:

Static analysis

No suspicious patterns detected.