gmgn-swap

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and its install/data flow appear consistent with official GMGN tooling, so this is not strong evidence of malware. However, it is intrinsically high risk because it grants an AI agent the ability to execute real crypto trades and strategy orders using local private-key-based authorization through an external CLI. Overall classification: SUSPICIOUS due to high-impact financial execution and sensitive credential use, not because of clear deception or exfiltration.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Apr 24, 2026, 06:42 AM
Package URL
pkg:socket/skills-sh/GMGNAI%2Fgmgn-skills%2Fgmgn-swap%2F@4888277249509fd6ce1f09451fa3ab61ff817bf2