T08 · Insecure Dependencies
- Location
SKILL.md:59- Finding
Unpinned Global Installation of a Third-Party CLI
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent GMGN market-data helper, but its setup asks the agent to install an unpinned global CLI and handle API/key material in ways users should review first.
Install only if you are comfortable with a global npm CLI and GMGN credentials on this machine. Prefer installing a reviewed, pinned gmgn-cli version yourself, use a secure secret-entry path for the API key, rotate or revoke the key if exposed, and avoid the first-time setup flow unless the temporary private key handling is fixed or performed manually in a secure location.
SKILL.md:59Unpinned Global Installation of a Third-Party CLI
SKILL.md:80Private Key Written to a Predictable Shared Temporary Path
SKILL.md:87API Key Exposed Through a Command-Line Argument
The description says to use the skill when the user asks for "what's pumping," "hot coins," or wants to "discover early-stage opportunities." These are open-ended, conversational phrases without clear scope boundaries or exclusion conditions, so they can collide with general market chat rather than explicit intent to use this specific GMGN market skill.
The skill instructs the agent to inspect local network interfaces and query an external IP-echo service for IPv6 troubleshooting, which exceeds the stated scope of market-data retrieval. This broad host/network inspection can disclose local network configuration and external addressing information unnecessarily, increasing privacy and environment-discovery risk if the skill is invoked in sensitive environments.
The setup flow instructs the agent to generate a new Ed25519 private key on the host, introducing credential-generation and secret-material handling beyond the skill's market-data purpose. Creating private keys on the agent host expands the blast radius if logs, temp files, shell history, or the host are compromised, and normalizes unnecessary secret management inside a data-retrieval skill.
The skill asks the user to provide an API key and stores it via CLI configuration without an explicit warning that the credential is sensitive or guidance on minimizing exposure. This increases the chance of users pasting secrets into conversational channels or allowing unnecessary persistence of credentials on shared systems.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Tell the user: *"This is your Ed25519 public key. Go to **https://gmgn.ai/ai**, paste it into the API key creation form, then send me the API Key value shown on the page."*
2. Wait for the user's API key, then save it with `gmgn-cli config` (creates `~/.config/gmgn/.env` and sets `chmod 600` automatically — do not hand-edit the file):
```bash
gmgn-cli config set-key <key_from_user>
No suspicious patterns detected.