gmgn-swap
Execute GMGN Token Swaps and Strategy Orders
Manual token trading across wallets and chains requires careful parameter handling. This skill prepares GMGN CLI operations with validation, quotes, and confirmation checkpoints.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "gmgn-swap" from https://skillstore.io/skills/gmgnai-gmgn-swap.md and its manifest at https://skillstore.io/api/skills/gmgnai-gmgn-swap/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "gmgn-swap". Quote swapping 0.1 SOL to a specified token on Solana.
Expected outcome:
Quote prepared: estimated token output, minimum output, slippage, wallet, and fees. No transaction was submitted.
Using "gmgn-swap". Sell 50 percent of a token balance for USDC.
Expected outcome:
Confirmation required: verified chain and addresses, percentage amount, estimated USDC proceeds, slippage, and fees.
Using "gmgn-swap". Check the result of a submitted swap.
Expected outcome:
Swap confirmed: human-readable spent and received amounts, transaction link, and order identifier.
Security Audit
CriticalThe skill intentionally executes irreversible trades through an external CLI and relies on API and wallet private keys stored in a hidden environment file. Most backtick findings are Markdown false positives, but credential solicitation, secret access, financial commands, network reconnaissance, and confirmation bypasses are confirmed. Publication should wait until credential collection and transaction approval controls are redesigned. Static review was capped at 400/430 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
Confirmed security concerns (13)
Show all 13 confirmed findings
Capability review items (34)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (50)
๐ Network access (7)
๐ Filesystem access (5)
๐ Env variables (11)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/gmgnai-gmgn-swap/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/gmgnai-gmgn-swap?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/gmgnai-gmgn-swap?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/gmgnai-gmgn-swap/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/gmgnai-gmgn-swap.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
gmgnai. (2026). gmgn-swap security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/gmgnai-gmgn-swap/audits/1BibTeX citation
@techreport{gmgnai-gmgnai-gmgn-swap-2026,
author = {gmgnai},
title = {gmgn-swap security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/gmgnai-gmgn-swap/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "gmgn-swap security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "gmgnai"
date-released: "2026-09-05"
url: "https://skillstore.io/skills/gmgnai-gmgn-swap/audits/1"
identifiers:
- type: other
value: "skillstore:gmgnai-gmgn-swap:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: LowWhat You Can Build
Confirm a Single Swap
Prepare a quoted token swap, review resolved addresses and fees, then submit after explicit approval.
Manage Exit Strategies
Create and monitor take-profit, stop-loss, or trailing orders for an existing token position.
Coordinate Wallet Batches
Prepare consistent trades across several linked wallets while preserving per-wallet amounts and results.
Try These Prompts
Quote swapping [amount] [input token] to [output token] on [chain] from [wallet]. Do not submit a transaction.
Prepare a swap of [amount] [input token] for [output token] on [chain]. Validate addresses, run safety checks, and show confirmation first.
Prepare a [take-profit or stop-loss] order for [token] on [chain] at [trigger]. Show amount, slippage, fees, and expiry before submission.
Prepare a multi-wallet swap on [chain] using these wallets and amounts: [details]. Add [conditions], validate every address, and require final confirmation.
Best Practices
- Verify contract addresses independently and complete token safety checks before every purchase.
- Review chain, wallet, smallest-unit conversion, slippage, fees, and expected output before confirming.
- Use small test amounts, anti-MEV protection where supported, and fresh approval for every transaction.
Avoid
- Do not send API keys or private keys through chat, command arguments, logs, or screenshots.
- Do not identify tokens by name alone or skip contract verification because a trade is urgent.
- Do not enable unattended trade submission or retry failed transactions without renewed confirmation.
Frequently Asked Questions
Does this skill move real funds?
Which credentials are required?
Can it find a token from its name?
Which networks are supported?
Can it trade across multiple wallets?
Can a completed swap be reversed?
Developer Details
Author
gmgnaiLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Repository
https://github.com/gmgnai/gmgn-skills/tree/aa4d29a9b7d1aaaac3d6acd72c13f17575605348/skills/gmgn-swapRef
e5464e662405de6361fdde6b984f9ea865635f64
Maintenance freshness
9/8/2026
Usage
0 downloads ยท 0 views
File structure
๐ SKILL.md