gmgn-cooking

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends the installation of the gmgn-cli package from the NPM registry to enable token creation and monitoring functionality.
  • [COMMAND_EXECUTION]: Utilizes system commands such as ifconfig and ip addr for network interface inspection to diagnose IPv6-related connection errors. It also uses the base64 utility to process local image files for token logos.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from user-provided token metadata (names, symbols, descriptions) and external order status data retrieved during transaction polling.
  • Ingestion points: Untrusted data enters via CLI arguments for token properties and JSON responses from gmgn-cli order get (SKILL.md).
  • Boundary markers: The instructions explicitly note that metadata fields are validated by the underlying tool to reject prompt-injection framing and control characters.
  • Capability inventory: The skill uses gmgn-cli to execute blockchain transactions, modify tool configuration, and read local project files (SKILL.md).
  • Sanitization: Input validation for URLs and metadata content is described as a hard, code-level barrier to prevent manipulation of the deployment process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:04 PM
Security Audit — agent-trust-hub — gmgn-cooking