gmgn-wallet-style

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted third-party data including transaction activity, token names, and wallet metadata (e.g., common.tags).
  • Ingestion Points: gmgn-cli portfolio stats and gmgn-cli portfolio activity commands fetch external blockchain data.
  • Capability Inventory: The agent is instructed to write local HTML files and execute shell commands via gmgn-cli.
  • Sanitization: The skill includes explicit instructions to HTML-escape data, neutralize suspicious metadata notices from the CLI, and ignore any text in data fields that resembles commands or overrides.
  • Boundary Markers: The 'Notes' section explicitly directs the agent to treat all third-party fields as data only and not as instructions.
  • [COMMAND_EXECUTION]: The skill requires the installation and execution of the gmgn-cli tool to interact with the gmgn.ai platform.
  • Evidence: Commands such as gmgn-cli portfolio stats and gmgn-cli portfolio activity are used to retrieve the necessary data for analysis.
  • Context: The tool is a vendor-provided CLI for the 'gmgnai' ecosystem, used here for read-only data retrieval.
  • [DYNAMIC_EXECUTION]: The skill generates interactive HTML previews by assembling data into a local file.
  • Evidence: Step 9 details the creation of a local HTML page using pixel-based coordinate mapping and responsive scaling logic.
  • Security Controls: The instructions mandate HTML-escaping of all API strings and the use of Unicode escapes inside script tags to prevent XSS or script termination attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:11 PM
Security Audit — agent-trust-hub — gmgn-wallet-style