litcoin-miner

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The Research Mining feature involves dynamic generation and local execution of Python code. AI-generated solutions are run locally by the SDK for testing purposes, which allows for the execution of arbitrary instructions on the host system.- [REMOTE_CODE_EXECUTION]: Skill documentation provides instructions to download and execute a remote script (litcoin_miner.py) from the vendor's domain (litcoiin.xyz) using Python.- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it processes untrusted prose narratives from the mining coordinator for comprehension challenges. Ingestion points include documents fetched from api.litcoiin.xyz. There are no boundary markers or sanitization procedures defined to prevent the agent from following malicious instructions embedded in these challenges.- [EXTERNAL_DOWNLOADS]: The skill requires the installation of external packages such as the litcoin Python library and litcoin-mcp Node.js package from public registries.- [COMMAND_EXECUTION]: The setup and operation of the mining tools involve executing shell commands such as pip install, npx, and python scripts.- [DATA_EXFILTRATION]: The skill handles the BANKR_API_KEY for DeFi operations and transmits data to the coordinator at api.litcoiin.xyz. While functional for the protocol, it involves managing sensitive financial credentials over the network.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 04:19 AM