gmgn-wallet-score

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local system commands such as ifconfig, ip addr show, and the gmgn-cli utility. These are used for network diagnostics and retrieving portfolio data.
  • [DYNAMIC_EXECUTION]: Logic for scoring and report generation is implemented in an inline Python script executed via a shell heredoc (python3 << 'PYEOF'). This is a standard method for performing complex calculations within a skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from blockchain activity, including token metadata and wallet names. This data is untrusted and could theoretically contain injection attempts, though the script's deterministic processing limits the risk.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the gmgn-cli tool from a public registry and makes a diagnostic network request to icanhazip.com to verify IPv6 status. These actions are transparently documented and support the skill's core functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:11 PM
Security Audit — agent-trust-hub — gmgn-wallet-score