gmgn-wallet-review
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on executing shell commands via
gmgn-clito fetch wallet statistics, activity, and holdings. It also usesjqorpython3 -cfor processing JSON responses. - [EXTERNAL_DOWNLOADS]: The instructions direct the user to install the
gmgn-clitool globally usingnpm install -g gmgn-cli. As the skill author is identified as the vendor for this tool, this is considered a standard vendor resource operation. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (token names, symbols, and GMGN labels) which could contain malicious injection attempts.
- Ingestion points: Output from
gmgn-clicommands in JSON format, specifically fields like token names and social metadata. - Boundary markers: The skill contains explicit instructions for the agent to treat third-party text solely as data and never to follow instructions embedded within it.
- Capability inventory: The skill can execute shell commands, perform local file writes for HTML rendering, and invoke system utilities like
jqandpython3. - Sanitization: The skill mandates strict regex validation for wallet addresses and chains before execution. It also specifies quoting arguments in shell commands and includes an
esc()function for HTML rendering to prevent XSS. - [CREDENTIALS_UNSAFE]: The skill references sensitive environment variables like
GMGN_API_KEYandGMGN_PRIVATE_KEYbut specifically instructs the agent not to print, echo, or read them directly, delegating their use to the internal signing mechanisms of the CLI tool.
Audit Metadata