Back to skill

Security audit

Litcoin Skill

Security checks across malware telemetry and agentic risk

Overview

This is a coherent LITCOIN mining and DeFi skill, but it gives agents write-capable wallet access and includes automatic public/permanent data sharing and autonomous financial workflows that need careful review.

Install only if you intentionally want an agent to interact with a real crypto wallet and this specific LITCOIN protocol. Use a dedicated low-balance wallet, avoid pasting real secrets into prompts or logs, require manual approval for every transaction and autonomous-agent configuration, set strict budgets, disable relay unless you explicitly want to serve third-party AI requests, and do not submit confidential prompts, code, or reasoning because research traces may be permanently public.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README advertises autonomous research, agent deployment, and full on-chain DeFi operations without any safety disclosures, approval requirements, or warnings about financial loss, privacy exposure, or system/resource consumption. In an agent-skill context, this omission is materially risky because integrators may enable capabilities that can spend funds, interact with external services, or run research tasks autonomously without understanding the operational and security consequences.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is overly broad and is likely to activate on generic crypto, AI-agent, or DeFi queries, causing the agent to route users into a high-risk financial skill when they may not have explicitly asked for it. In this context, over-triggering is dangerous because the skill includes wallet-linked, on-chain, and external-network operations that can lead to unintended financial actions or credential use.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill promotes autonomous scheduled mining, research, and claiming via cron without prominently warning that this can trigger repeated network calls, API consumption, local resource use, and on-chain transactions with gas costs. Because the schedule can run indefinitely and claim automatically based on thresholds, users may incur ongoing financial and operational consequences without understanding the persistence of the automation.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill documents staking, vaults, minting, collateral withdrawal, escrow deposits, and guild pooling without any clear risk disclosure about loss of funds, liquidation, lockups, smart-contract risk, or stablecoin debt exposure. In a DeFi context, presenting these operations as routine SDK calls materially increases the chance that users perform financially impactful actions without informed consent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill quickly moves users into value-affecting operations such as swaps, claims, staking, vaults, minting, and autonomous agent deployment without a clear, general upfront warning that these actions can spend funds, lock assets, incur gas costs, or trigger irreversible on-chain transactions. In a crypto/DeFi skill, omission of explicit financial-risk consent is dangerous because users may authorize real transactions before understanding consequences.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The research mining section states that chain-of-thought or reasoning traces are automatically captured, stored permanently, and displayed publicly, but it does not present this as a privacy/security warning. This is dangerous because users may unknowingly submit sensitive prompts, internal reasoning, credentials, proprietary logic, or regulated data to permanent third-party storage.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation states that providing an AI API key automatically turns the miner into a relay provider, but it does not clearly warn that third-party prompts and inference data may be processed through the user's configured model endpoint. In a skill intended for autonomous agents, this can cause unanticipated external data handling, privacy exposure, and unexpected API spend simply by enabling an API key for a different feature.

Missing User Warnings

High
Confidence
98% confidence
Finding
The protocol claims the SDK automatically captures chain-of-thought and submits it for permanent archival, without a strong privacy and secrecy warning. Reasoning traces can contain sensitive inputs, secrets, internal instructions, or proprietary logic, and permanent storage materially increases the blast radius because data cannot be meaningfully recalled once uploaded.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.