T08 · Insecure Dependencies
- Location
SKILL.md:79- Finding
Unpinned Global Installation of a Transaction-Capable npm Package
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is openly designed to perform real crypto token launches, but its setup and credential handling create review-worthy risk around signing keys, workspace secrets, and unpinned global software installation.
Install only if you understand that this skill can help deploy real tokens and spend real funds. Use a dedicated low-balance wallet, avoid placing GMGN secrets in project .env files, review the gmgn-cli package and version before installing it globally, and reconfirm all fee-share, buyback, and auto-sell settings before every launch.
SKILL.md:79Unpinned Global Installation of a Transaction-Capable npm Package
SKILL.md:81Transaction-Capable Credentials May Be Stored in an Untrusted Workspace
SKILL.md:107Private Key Generated at a Predictable Temporary Path Without Cleanup
The first-time setup flow expands the skill from token launching into credential provisioning: it generates a private key, asks the user to obtain an API key, and writes both secrets to disk in ~/.config/gmgn/.env. This is highly sensitive because it establishes long-lived signing capability for real financial transactions, creates persistent secret material on the host, and normalizes the agent handling credentials beyond its core task.
The skill instructs the agent to run host/network diagnostic commands (ifconfig, ip addr, external IPv6 check) that are not necessary to fulfill the core business action of token creation or stats lookup. These commands expose local network configuration and outbound IP information, expanding the skill's access to sensitive environment data and creating unnecessary system reconnaissance capability.
The skill tells the agent to globally install software with npm install -g gmgn-cli, which exceeds the narrow scope of using an existing tool to create tokens or query stats. Allowing package installation grants code execution from an external package source, increases supply-chain risk, and mutates the host environment in a way unrelated to the immediate user request.
The skill explicitly instructs the agent to retain and reuse advanced settings across future launches, which is risky in a financial-execution context. Reusing prior fee-share or auto-sell parameters can silently alter future token launches, routing value to prior recipients or triggering unintended trades if the user assumes defaults on a later interaction.
The instruction to save advanced launch settings to memory introduces state retention unrelated to the one-shot execution of a token launch. Persisting fee splits, buyback settings, or other financial preferences can cause privacy issues or unintended reuse in later transactions if the stored state is stale, misapplied, or accessed in a different context.
No suspicious patterns detected.