Back to skill

Security audit

GMGN Skill Cooking

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly designed to perform real crypto token launches, but its setup and credential handling create review-worthy risk around signing keys, workspace secrets, and unpinned global software installation.

Install only if you understand that this skill can help deploy real tokens and spend real funds. Use a dedicated low-balance wallet, avoid placing GMGN secrets in project .env files, review the gmgn-cli package and version before installing it globally, and reconfirm all fee-share, buyback, and auto-sell settings before every launch.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:79
Finding

Unpinned Global Installation of a Transaction-Capable npm Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:81
Finding

Transaction-Capable Credentials May Be Stored in an Untrusted Workspace

Content
View full analysis
/dev/null && echo "WARNING: local .env is overriding ~/.config/gmgn/.env" ``` If a local `.env` exists but lacks `GMGN_API_KEY` / `GMGN_PRIVATE_KEY`, either add them to that file or remove it so the global config is used. ``` ### Technical Analysis The Skill documents that a workspace-level `.env` overrides the trusted user configuration and explicitly recommends adding the GMGN API key and private key to that workspace file as a recovery option. A project workspace is not an appropriate trust boundary for transaction-capable secrets. Workspace files may be committed to source control, indexed by development tools, included in archives or backups, exposed to collaborators, or read by project-specific scripts. A malicious or merely misconfigured repository can also pre-create a local `.env` that shadows the expected global configuration. The command used to detect the file only lists its metadata and does not reveal its contents, which is appropriate. The vulnerability arises from the precedence model and the recommendation to copy high-impact credentials into the workspace. Reading a signing credential is necessary for token deployment, but allowing an arbitrary current directory to override the credential source and encouraging workspace storage exceed minimum privilege. ### Attack Path 1. A user opens or clones an untrusted, shared, or compromised repository containing a local `.env`. 2. The Agent runs `gmgn-cli` from that repository. ...[truncated 1343 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:107
Finding

Private Key Generated at a Predictable Temporary Path Without Cleanup

Content
View full analysis
/dev/null && \ openssl pkey -in /tmp/gmgn_private.pem -pubout 2>/dev/null ``` ### Technical Analysis The setup procedure writes a private signing key to the fixed path `/tmp/gmgn_private.pem`. Shared temporary directories are generally writable by multiple local principals. A predictable filename creates avoidable exposure to local file-race, pre-creation, replacement, or symbolic-link attacks, depending on operating-system protections and OpenSSL's file-opening behavior. The documented flow does not create a private temporary directory, verify that the destination is a regular file owned by the current user, explicitly enforce restrictive permissions before writing, or remove the temporary private key after copying its content to the final credential file. Suppressing standard error with `2>/dev/null` also obscures permission, path, and file-handling failures that could indicate unsafe setup conditions. ### Attack Path 1. A local attacker learns the documented fixed path and monitors or prepares `/tmp/gmgn_private.pem`. 2. The Agent executes the setup command. 3. Depending on platform protections and file state, the attacker reads the generated file, interferes with its creation, or redirects the write through a filesystem link. 4. The setup process copies the resulting private-key material into the GMGN configuration. 5. The temporary file remains at the predictable path because no cleanup is specified. 6. The attacker obtains the signing key or causes an attacker-controlled key to be configured, enabling later transaction abuse. Even without a race condition, residual key material may remain readable after setup if effective permissions, ownership, or system configuration are weaker than expecte ...[truncated 535 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The first-time setup flow expands the skill from token launching into credential provisioning: it generates a private key, asks the user to obtain an API key, and writes both secrets to disk in ~/.config/gmgn/.env. This is highly sensitive because it establishes long-lived signing capability for real financial transactions, creates persistent secret material on the host, and normalizes the agent handling credentials beyond its core task.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to run host/network diagnostic commands (ifconfig, ip addr, external IPv6 check) that are not necessary to fulfill the core business action of token creation or stats lookup. These commands expose local network configuration and outbound IP information, expanding the skill's access to sensitive environment data and creating unnecessary system reconnaissance capability.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill tells the agent to globally install software with npm install -g gmgn-cli, which exceeds the narrow scope of using an existing tool to create tokens or query stats. Allowing package installation grants code execution from an external package source, increases supply-chain risk, and mutates the host environment in a way unrelated to the immediate user request.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill explicitly instructs the agent to retain and reuse advanced settings across future launches, which is risky in a financial-execution context. Reusing prior fee-share or auto-sell parameters can silently alter future token launches, routing value to prior recipients or triggering unintended trades if the user assumes defaults on a later interaction.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instruction to save advanced launch settings to memory introduces state retention unrelated to the one-shot execution of a token launch. Persisting fee splits, buyback settings, or other financial preferences can cause privacy issues or unintended reuse in later transactions if the stored state is stale, misapplied, or accessed in a different context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.