Litcoin Skill
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's stated purpose (mining LITCOIN on Base) is broadly consistent with its instructions, but it asks you to install/run external code (pip package and curl-downloaded scripts) and to supply a Bankr API key with write/agent privileges — actions that are high-risk and deserve caution.
Before installing or running this skill: 1) Understand that providing BANKR_API_KEY with agent/write permissions lets the service submit on-chain transactions on your behalf — only supply it if you trust the service and expect claims/staking. 2) The SKILL.md recommends installing a PyPI package and (in docs) downloading a Python script from https://litcoiin.xyz; treat these as untrusted code until you review their source. 3) Prefer to audit the 'litcoin' package source (PyPI/Git) and inspect any downloaded scripts before execution, or run in an isolated environment. 4) If you only want read-only info, avoid enabling Bankr agent write access; use a separate read-only key or limit privileges. 5) If you plan to enable autonomous cron mining, review the cron commands and tokens carefully and consider rate/expense/gas implications. If you want more confidence, provide the maintainer's upstream repository or the litcoin package source so it can be inspected.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
