skills/gmgnai/gmgn-skills/gmgn-swap/Gen Agent Trust Hub

gmgn-swap

Warn

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXFILTRATION]: The skill reads from a configuration file at ~/.config/gmgn/.env which is used to store sensitive API keys and private keys required for transaction signing.
  • [DATA_EXFILTRATION]: The skill includes diagnostic instructions to query https://ipv6.icanhazip.com, a well-known service used to determine the public IP address of the execution environment.
  • [COMMAND_EXECUTION]: The skill uses the gmgn-cli command-line tool to perform swaps, query order statuses, and create trading strategies.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install an external dependency, gmgn-cli, via the NPM global registry.
  • [PROMPT_INJECTION]: The skill contains strong instructional language and warnings designed to ensure safe financial execution and prevent common blockchain transaction errors, but these do not attempt to override the core safety guidelines of the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 24, 2026, 06:40 AM