qrcoin
Fail
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The primary domain associated with this skill,
https://qrcoin.fun, is flagged as malicious by automated URL scanners and is currently blacklisted. - [METADATA_POISONING]: The
SKILL.mdfile itself has a confirmed malicious detection by reputation scanners (FileRepMalware). - [EXTERNAL_DOWNLOADS]: The skill fetches auction data from the Base blockchain's public RPC endpoint at
https://mainnet.base.organd references a remote repository on GitHub (github.com/BankrBot/skills). - [INDIRECT_PROMPT_INJECTION]: The skill incorporates external data from blockchain RPC calls into the agent's context.
- Ingestion points: Data retrieved via
curlfromhttps://mainnet.base.orginSKILL.mdis piped into the agent's workflow. - Boundary markers: No delimiters or instructions are present to prevent the agent from obeying instructions that might be embedded in the retrieved blockchain data.
- Capability inventory: The skill uses
curlandjqfor network queries and instructs the agent to use the 'Bankr' skill for transaction execution. - Sanitization: The skill uses
jqto parse JSON structure but lacks content sanitization or verification of the fetched data. - [COMMAND_EXECUTION]: Instructions guide the agent to execute shell commands using
curlandjqto fetch and parse data from external network sources, creating a path for processing untrusted remote content.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata