Back to skill

Security audit

GMGN Skill Market

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent GMGN market-data helper, but its setup asks the agent to install an unpinned global CLI and handle API/key material in ways users should review first.

Install only if you are comfortable with a global npm CLI and GMGN credentials on this machine. Prefer installing a reviewed, pinned gmgn-cli version yourself, use a secure secret-entry path for the API key, rotate or revoke the key if exposed, and avoid the first-time setup flow unless the temporary private key handling is fixed or performed manually in a secure location.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:59
Finding

Unpinned Global Installation of a Third-Party CLI

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:80
Finding

Private Key Written to a Predictable Shared Temporary Path

Content
View full analysis
/dev/null && \ openssl pkey -in /tmp/gmgn_private.pem -pubout 2>/dev/null ``` The Skill then instructs the user to register the displayed public key: ```text This is your Ed25519 public key. Go to https://gmgn.ai/ai, paste it into the API key creation form, then send me the API Key value shown on the page. ``` ### Technical Analysis The setup procedure writes an Ed25519 private key to the fixed path `/tmp/gmgn_private.pem`. Shared temporary directories are commonly writable by multiple local users. A predictable filename can therefore create symlink, race-condition, overwrite, and disclosure risks. The command does not explicitly establish a restrictive `umask`, verify that the destination is a newly created regular file, or remove the private key after enrollment. Although OpenSSL may apply restrictive defaults on some systems, the Skill should not rely on environment-specific behavior when handling private key material. The document later states that operational authentication uses an API key only. It does not explain a continuing need to retain the generated private key after the public key has been registered. Leaving that file behind therefore exceeds the apparent minimum data-retention requirement. ### Attack Path 1. An attacker with access to the same host predicts the fixed `/tmp/gmgn_private.pem` filename. 2. Before setup, the attacker creates a conflicting filesystem object, such as a symbolic link, or monitors the path for creation. 3. The Agent runs the documented OpenSSL command. 4. Depending on platform protections and filesystem state, the command may overwrite an unintended user-writable target or create private key material at a path observable by the attacker ...[truncated 812 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:87
Finding

API Key Exposed Through a Command-Line Argument

Content
View full analysis
``` The surrounding instruction is: ```text Wait for the user's API key, then save it with gmgn-cli config (creates ~/.config/gmgn/.env and sets chmod 600 automatically — do not hand-edit the file). ``` ### Technical Analysis The Skill directs the Agent to substitute a user-provided API key into a command-line argument. Process arguments may be observable through process-inspection facilities, diagnostic tooling, audit systems, shell history, terminal capture, or Agent execution transcripts. Applying mode `0600` to `~/.config/gmgn/.env` protects the credential after storage but does not protect it while it is present in the process argument vector. The credential may also persist in orchestration or tool-call logs after the command terminates. The API key is necessary for the declared API functionality, and storing it in a user-restricted configuration file is consistent with that purpose. Passing it through an exposed argument channel, however, is not the least-risk method of provisioning it. ### Attack Path 1. The user sends the GMGN API key to the Agent as instructed. 2. The Agent interpolates the value into `gmgn-cli config set-key `. 3. The complete command or argument vector is captured by process monitoring, shell history, Agent logs, terminal recording, or system audit infrastructure. 4. A local user or party with access to retained logs recovers the key. 5. The attacker uses the key to make authenticated GMGN API requests as the victim until the credential is revoked or expires. ### Impact Assessment An attacker who recovers the key can impersonate the user to the extent permitted by the GMGN API credential. Expected consequences include unauthorized API usage, consumption of rate limits or quo ...[truncated 320 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use the skill when the user asks for "what's pumping," "hot coins," or wants to "discover early-stage opportunities." These are open-ended, conversational phrases without clear scope boundaries or exclusion conditions, so they can collide with general market chat rather than explicit intent to use this specific GMGN market skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to inspect local network interfaces and query an external IP-echo service for IPv6 troubleshooting, which exceeds the stated scope of market-data retrieval. This broad host/network inspection can disclose local network configuration and external addressing information unnecessarily, increasing privacy and environment-discovery risk if the skill is invoked in sensitive environments.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The setup flow instructs the agent to generate a new Ed25519 private key on the host, introducing credential-generation and secret-material handling beyond the skill's market-data purpose. Creating private keys on the agent host expands the blast radius if logs, temp files, shell history, or the host are compromised, and normalizes unnecessary secret management inside a data-retrieval skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill asks the user to provide an API key and stores it via CLI configuration without an explicit warning that the credential is sensitive or guidance on minimizing exposure. This increases the chance of users pasting secrets into conversational channels or allowing unnecessary persistence of credentials on shared systems.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

text
   Tell the user: *"This is your Ed25519 public key. Go to **https://gmgn.ai/ai**, paste it into the API key creation form, then send me the API Key value shown on the page."*

2. Wait for the user's API key, then save it with `gmgn-cli config` (creates `~/.config/gmgn/.env` and sets `chmod 600` automatically — do not hand-edit the file):
   ```bash
   gmgn-cli config set-key <key_from_user>

Static analysis

No suspicious patterns detected.