Back to skill

Security audit

Litcoin

Security checks across malware telemetry and agentic risk

Overview

This LITCOIN mining skill is coherent with its crypto/DeFi purpose, but it gives agents high-impact wallet authority and documents automatic relay and permanent reasoning-trace behaviors that users should review carefully.

Install only if you intentionally want an agent to manage LITCOIN wallet actions. Use a dedicated wallet and scoped Bankr key if possible, keep limited funds available, pin and inspect the SDK/MCP versions before use, disable relay unless you knowingly want to serve third-party inference, and avoid research mining with private prompts or sensitive context because reasoning traces may be archived publicly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill advertises a very broad set of cryptocurrency, DeFi, staking, vault, minting, and agent-deployment capabilities, which increases the chance it will be invoked for sensitive financial actions without narrow user intent verification. In this context, overly broad activation is dangerous because the documented operations can trigger real on-chain transactions and asset movements on Base.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README documents real financial and on-chain operations such as claiming, staking, vault collateralization, minting credit, escrow deposits, and early unstaking penalties, but does not prominently warn that these actions can spend funds, lock assets, incur fees, or create debt. In a crypto/DeFi skill, omission of explicit risk disclosure materially increases the chance of unsafe use and unintended financial loss.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation states that the SDK automatically captures chain-of-thought reasoning and stores it permanently, but it does not present this as a prominent privacy/security warning or require explicit opt-in. Reasoning traces can contain sensitive prompts, hidden context, secrets, or proprietary data, and permanent archival materially increases exposure and retention risk.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The documentation says relay mining starts automatically when an AI API key is supplied, but it does not foreground that the user's provider credentials will be used to serve third-party inference traffic. This can create unexpected cost exposure, policy violations, abuse handling burden, and leakage of model access to unanticipated workloads.

Ssd 3

Medium
Confidence
95% confidence
Finding
Automatically capturing and permanently archiving model reasoning traces creates a direct data-exfiltration and over-retention risk, especially if prompts include user secrets, proprietary data, or hidden prompt instructions. In an agent skill context, this is more dangerous because agent workflows may process sensitive task context without the operator realizing it will be transmitted and stored.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.