gmgn-swap
Warn
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXFILTRATION]: The skill reads from a configuration file at
~/.config/gmgn/.envwhich is used to store sensitive API keys and private keys required for transaction signing. - [DATA_EXFILTRATION]: The skill includes diagnostic instructions to query
https://ipv6.icanhazip.com, a well-known service used to determine the public IP address of the execution environment. - [COMMAND_EXECUTION]: The skill uses the
gmgn-clicommand-line tool to perform swaps, query order statuses, and create trading strategies. - [EXTERNAL_DOWNLOADS]: The skill instructs the user to install an external dependency,
gmgn-cli, via the NPM global registry. - [PROMPT_INJECTION]: The skill contains strong instructional language and warnings designed to ensure safe financial execution and prevent common blockchain transaction errors, but these do not attempt to override the core safety guidelines of the agent.
Audit Metadata