mirror of
https://github.com/GMGNAI/gmgn-skills.git
synced 2026-08-18 02:28:07 +00:00
fix(security): defend against prompt injection via token metadata
Address HackenProof report GMGNWM-143, where attacker-controlled token metadata could hijack an AI agent driving gmgn-cli into executing an unauthorized trade. Move guardrails from overridable SKILL.md text into code. - Add src/sanitize.ts: neutralize prompt-injection framing and hidden/control characters in API output (via printResult) and validate create-token metadata - Add src/confirm.ts: code-enforced human confirmation for financial writes (swap, multi-swap, order strategy create, cooking create) — reads a typed "yes" from /dev/tty; automation requires GMGN_ALLOW_AUTOMATED_TRADES=1 + --yes - Harden config.ts: tighten ~/.config/gmgn/.env to 0600 and warn if world-readable - Update SKILL.md files, Readme.md and Readme.zh.md to document the gate, the --yes flag, and untrusted-metadata handling Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
b18d7deb32
commit
fdc7a3fb16
+8
-2
@@ -1,8 +1,14 @@
|
||||
import { sanitizeForOutput } from "./sanitize.js";
|
||||
|
||||
export function printResult(data: unknown, raw?: boolean): void {
|
||||
// Neutralize any attacker-controlled metadata (token name/symbol/description/
|
||||
// social links, on-chain URIs, etc.) before it is emitted and read by an AI
|
||||
// agent. Defends against indirect prompt injection via token metadata.
|
||||
const safe = sanitizeForOutput(data);
|
||||
if (raw) {
|
||||
console.log(JSON.stringify(data));
|
||||
console.log(JSON.stringify(safe));
|
||||
} else {
|
||||
console.log(JSON.stringify(data, null, 2));
|
||||
console.log(JSON.stringify(safe, null, 2));
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user