Litcoin
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's stated purpose (mining LITCOIN with a Bankr wallet) mostly matches what it asks for, but there are multiple operational and trust risks — notably automatic relay behavior, requests for a write-capable Bankr API key, and instructions to install or download code from an external site — that you should review before installing or running.
Before installing or running this skill: (1) Treat the BANKR_API_KEY as high‑risk — it requests write access that can sign transactions and move tokens; prefer a least-privilege or watch-only key if possible. (2) Do not blindly run the suggested pip install or curl download: inspect the PyPI package contents and the script from https://litcoiin.xyz in a safe sandbox first. (3) Be aware that providing an AI key may make your node serve inference requests for others (possible billing/exposure); only provide keys you control and monitor usage. (4) The skill records and submits chain‑of‑thought traces to a permanent archive — avoid submitting private data or proprietary prompts. (5) Verify contract addresses, the project website reputation, and open-source code (if available) before granting any credentials. If you are not comfortable auditing remote code or managing potential on‑chain operations, do not install or run this skill.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
Risk analysis
No visible risk-analysis findings were reported for this release.
