litcoin-miner
Fail
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation (README.md and docs.md) instructs users to download a standalone miner script from an external URL:
https://litcoin.app/litcoin_miner.py. - [REMOTE_CODE_EXECUTION]: The skill documentation encourages direct execution of the downloaded remote script using the shell:
python litcoin_miner.py. This pattern allows for the execution of arbitrary code not contained within the skill's source repository. - [REMOTE_CODE_EXECUTION]: The skill requires the installation of the
litcoinPython package from PyPI, which is an external dependency not managed or pinned within the skill itself. - [DYNAMIC_EXECUTION]: The 'Research Mining' feature involves the dynamic generation of Python code by an LLM at runtime, which is then executed locally by the SDK ('Agent tests the solution locally') to verify improvements against a baseline. This represents a significant risk of executing arbitrary code generated from external inputs.
- [INDIRECT_PROMPT_INJECTION]: The skill processes research tasks fetched from a remote coordinator (
api.litcoin.app). These tasks serve as untrusted data that influence the LLM's code generation process. A maliciously crafted task could induce the LLM to generate harmful code that is then executed during the local testing phase of the research loop. - Ingestion points: Research tasks are fetched via the
Agent.research_tasks()andAgent.research_mine()methods fromapi.litcoin.app. - Boundary markers: No explicit boundary markers or 'ignore embedded instructions' warnings are documented for the research task processing.
- Capability inventory: The skill executes dynamically generated Python code locally and performs network operations to
api.litcoin.appand various AI providers. - Sanitization: While the documentation mentions a server-side sandbox for verification, the local execution ('Agent tests the solution locally') lacks documented sanitization or isolation mechanisms.
Recommendations
- AI detected serious security threats
Audit Metadata