litcoin-miner
Audited by Socket on Mar 14, 2026
2 alerts found:
Securityx2SUSPICIOUS. The skill's stated purpose is openly crypto/DeFi, so its capabilities align with its description, but that purpose is itself high-risk for an AI agent. The major concerns are autonomous financial actions, forwarding wallet-linked and AI credentials to third-party services, routing OpenAI-compatible traffic through api.litcoiin.xyz, and unverified package provenance for software that can move value.
SUSPICIOUS. The skill’s crypto/DeFi capabilities broadly match its stated purpose, but its actual footprint is high risk: it forwards AI credentials and OpenAI-style traffic through a third-party relay, requires unrelated Bankr credentials, and enables autonomous token/DeFi actions on a schedule. Install paths are less concerning than the credential routing and unattended financial operations.