gmgn-wallet-review

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing shell commands via gmgn-cli to fetch wallet statistics, activity, and holdings. It also uses jq or python3 -c for processing JSON responses.
  • [EXTERNAL_DOWNLOADS]: The instructions direct the user to install the gmgn-cli tool globally using npm install -g gmgn-cli. As the skill author is identified as the vendor for this tool, this is considered a standard vendor resource operation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (token names, symbols, and GMGN labels) which could contain malicious injection attempts.
  • Ingestion points: Output from gmgn-cli commands in JSON format, specifically fields like token names and social metadata.
  • Boundary markers: The skill contains explicit instructions for the agent to treat third-party text solely as data and never to follow instructions embedded within it.
  • Capability inventory: The skill can execute shell commands, perform local file writes for HTML rendering, and invoke system utilities like jq and python3.
  • Sanitization: The skill mandates strict regex validation for wallet addresses and chains before execution. It also specifies quoting arguments in shell commands and includes an esc() function for HTML rendering to prevent XSS.
  • [CREDENTIALS_UNSAFE]: The skill references sensitive environment variables like GMGN_API_KEY and GMGN_PRIVATE_KEY but specifically instructs the agent not to print, echo, or read them directly, delegating their use to the internal signing mechanisms of the CLI tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:11 PM
Security Audit — agent-trust-hub — gmgn-wallet-review