skills/gmgnai/gmgn-skills/gmgn-token/Gen Agent Trust Hub

gmgn-token

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill explicitly identifies token metadata as untrusted, attacker-controlled data and provides clear instructions for the agent to neutralize potential prompt injection attempts found in token descriptions or names. It instructs the agent to ignore embedded instructions and treat the content purely as display data.
  • [COMMAND_EXECUTION]: The skill utilizes the gmgn-cli tool for its primary functions. It includes fallback instructions for configuration checks and network diagnostics (using ifconfig or ip addr) to troubleshoot IPv6 connectivity issues, which are appropriate for the tool's operating context and the author's infrastructure requirements.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of gmgn-cli via the official NPM registry. This is a standard and expected dependency for the skill's stated purpose of providing a CLI interface for the GMGN platform.
  • [DATA_EXFILTRATION]: The skill uses icanhazip.com, a well-known and reputable service, to verify public IP address versions for connectivity troubleshooting. This is documented neutrally as a diagnostic step and does not constitute unauthorized data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:04 PM
Security Audit — agent-trust-hub — gmgn-token