gmgn-track
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
gmgn-clitool for its primary operations. It also executes system diagnostic commands such asifconfigandip addr showto troubleshoot network connectivity issues related to IPv6 support. - [EXTERNAL_DOWNLOADS]: The skill directs the installation of the
gmgn-clipackage globally via npm to provide the necessary execution environment. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from the GMGN API, including wallet tags, token symbols, and social media metadata, which could be used as a vector for indirect prompt injection.
- Ingestion points: Data is retrieved from the GMGN API via several sub-commands like
track follow-wallet,track kol, andtrack smartmoneyas specified inSKILL.md. - Boundary markers: The instructions do not define any specific delimiters or clear instructions for the agent to ignore potentially malicious content within the fetched data.
- Capability inventory: The agent has the capability to execute shell commands through the CLI tool, perform network requests, and manage local configuration files.
- Sanitization: No data validation or sanitization mechanisms are described for handling the content received from the external API.
Audit Metadata