Litcoin Miner
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's requirements and instructions mostly match a mining use case (Bankr API + SDK), but several instructions could unintentionally expose keys, incur costs, or cause data (including chain-of-thought) to be published — and the README encourages downloading/running code from an external site; these behaviours deserve caution before installing.
This skill appears to be what it claims (a miner), but proceed cautiously. Before installing or running anything: (1) Understand you must give your BANKR_API_KEY with write permissions — this lets the SDK submit transactions from your wallet (ensure you trust bankr.bot and use a dedicated key/wallet with only small funds). (2) Do not set an AI key unless you intend your key to be used as a relay (it may serve requests for others and incur usage charges). (3) Be aware the protocol/SDK documents that chain-of-thought and verified code are archived permanently — do not submit sensitive data or private code. (4) Prefer inspecting the litcoin package source on PyPI or its repository before pip installing; avoid blindly running curl downloads from litcoiin.xyz. (5) If unsure, create a throwaway/test wallet and API keys with limited funds/permissions and review the SDK's source; consider refusing to set write-enabled keys or the AI key. These steps will reduce the risk of accidental fund loss, key misuse, or unwanted data publication.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
