gmgn-wallet-style
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted third-party data including transaction activity, token names, and wallet metadata (e.g.,
common.tags). - Ingestion Points:
gmgn-cli portfolio statsandgmgn-cli portfolio activitycommands fetch external blockchain data. - Capability Inventory: The agent is instructed to write local HTML files and execute shell commands via
gmgn-cli. - Sanitization: The skill includes explicit instructions to HTML-escape data, neutralize suspicious metadata notices from the CLI, and ignore any text in data fields that resembles commands or overrides.
- Boundary Markers: The 'Notes' section explicitly directs the agent to treat all third-party fields as data only and not as instructions.
- [COMMAND_EXECUTION]: The skill requires the installation and execution of the
gmgn-clitool to interact with the gmgn.ai platform. - Evidence: Commands such as
gmgn-cli portfolio statsandgmgn-cli portfolio activityare used to retrieve the necessary data for analysis. - Context: The tool is a vendor-provided CLI for the 'gmgnai' ecosystem, used here for read-only data retrieval.
- [DYNAMIC_EXECUTION]: The skill generates interactive HTML previews by assembling data into a local file.
- Evidence: Step 9 details the creation of a local HTML page using pixel-based coordinate mapping and responsive scaling logic.
- Security Controls: The instructions mandate HTML-escaping of all API strings and the use of Unicode escapes inside script tags to prevent XSS or script termination attacks.
Audit Metadata