Back to skill

Security audit

gate-info-tokenonchain

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only Gate-Info skill for token on-chain reports, with a minor routing-scope caveat but no hidden code, credentials, persistence, or destructive behavior.

Install if you are comfortable using the local Gate-Info MCP server for read-only token market and on-chain lookups. Treat outputs as informational rather than trading advice, and use separate reviewed skills for address tracking, general coin analysis, risk checks, or unsupported Smart Money analysis.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger scenarios are broad and underspecified, such as generic phrases like 'analyze SOL' or 'on-chain chip analysis', which can cause the host agent to invoke this skill for loosely related requests. This is risky because overbroad routing can lead to incorrect tool use, user confusion, or accidental disclosure of unrelated analysis, though the listed tools are read-only so the direct security impact is limited.

Static analysis

No suspicious patterns detected.