Back to skill

Security audit

Botcoin Miner

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed cryptocurrency node and mining setup, with important opt-out settings users should review before running it.

Install this only if you intend to run a cryptocurrency node and CPU miner. Before running the installer, inspect the upstream scripts, consider START_MINER=0 and AUTO_ACCEPT_NETWORK_PATCH_HASH=0, keep RPC access bound to 127.0.0.1, and expect CPU, disk, power, and network usage.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The quickstart prominently instructs users to run ./install.sh, while later documentation reveals START_MINER defaults to 1, meaning a CPU miner may be started automatically. Starting mining without an explicit upfront warning can consume significant CPU, degrade system performance, increase power usage, and surprise users in environments where background compute activity is unacceptable.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal