botcoin-miner
Audited by Socket on Mar 8, 2026
1 alert found:
Obfuscated FileOverall, the skill presents a coherent but high-risk capability: it orchestrates on-chain mining activity via Bankr, requiring privileged credentials and direct transaction submissions. The footprint shows significant credential exposure potential, reliance on unverifiable external sources, and autonomous financial actions. While the intended purpose (mining BOTCOIN) is plausible, the combination of non-standard distribution (unverifiable binaries), extensive credential flows, and multi-endpoint network interactions elevates security concerns. Treat as SUSPICIOUS to HIGH RISK pending stronger supply-chain controls, verifiable dependencies, and explicit per-action user consent prompts for on-chain operations.