skills/metamask/skills/gator-cli/Gen Agent Trust Hub

gator-cli

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill documentation explicitly states that the gator CLI stores private keys in plaintext JSON files located at ~/.gator-cli/profiles/. It also identifies configuration fields for apiKey and apiKeyId within the configuration file.
  • [EXTERNAL_DOWNLOADS]: The skill installs the @metamask/gator-cli package globally via npm. This is an official resource from the identified vendor.
  • [COMMAND_EXECUTION]: The skill provides instructions for executing various shell commands (gator init, gator create, gator redeem, etc.) to perform blockchain operations, including account upgrades and transaction signing.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 01:51 PM
Security Audit — agent-trust-hub — gator-cli