kryptogo-meme-trader
Enables analysis and trading of meme coins using KryptoGO's on-chain analysis platform, focusing on wallet clustering and automated trading.
Install this skill
Security score
The kryptogo-meme-trader skill was audited on Mar 5, 2026 and we found 53 security issues across 2 threat categories. Review the findings below before installing.
Categories Tested
Security Issues
Access to hidden dotfiles in home directory
| 39 | - filesystem:write:~/.openclaw/workspace/.env |
Access to hidden dotfiles in home directory
| 40 | - filesystem:write:~/.openclaw/workspace/memory/ |
Access to hidden dotfiles in home directory
| 50 | credential_file_read_note: "Only scripts/setup.py reads and writes ~/.openclaw/workspace/.env for initial keypair generation and address repair. All other scripts access credentials exclusively via pr |
Access to hidden dotfiles in home directory
| 87 | 2. Add to `~/.openclaw/workspace/.env`: |
Access to hidden dotfiles in home directory
| 89 | echo 'KRYPTOGO_API_KEY=sk_live_YOUR_KEY' >> ~/.openclaw/workspace/.env && chmod 600 ~/.openclaw/workspace/.env |
Access to hidden dotfiles in home directory
| 111 | - Runtime scripts do NOT read `.env` directly — all credentials are accessed via environment variables only, which must be pre-loaded by the caller (`source ~/.openclaw/workspace/.env`) |
Access to hidden dotfiles in home directory
| 136 | source ~/.openclaw/workspace/.env |
Access to hidden dotfiles in home directory
| 188 | Runtime scripts in this skill do NOT read `.env` files directly. All credentials are accessed via environment variables only, which must be pre-loaded by the caller (`source ~/.openclaw/workspace/.env |
Access to hidden dotfiles in home directory
| 200 | source ~/.openclaw/workspace/.env && bash scripts/cron-examples.sh setup-default |
Access to hidden dotfiles in home directory
| 203 | source ~/.openclaw/workspace/.env && bash scripts/cron-examples.sh setup-autonomous |
Access to hidden dotfiles in home directory
| 263 | source ~/.openclaw/workspace/.env && python3 scripts/swap.py <token_mint> 0.1 |
Access to hidden dotfiles in home directory
| 264 | source ~/.openclaw/workspace/.env && python3 scripts/swap.py <token_mint> <amount> --sell |
Access to hidden dotfiles in home directory
| 315 | All scripts require credentials to be pre-loaded: `source ~/.openclaw/workspace/.env` before running. |
Access to hidden dotfiles in home directory
| 318 | source ~/.openclaw/workspace/.env && bash scripts/portfolio.sh # Portfolio check |
Access to hidden dotfiles in home directory
| 319 | source ~/.openclaw/workspace/.env && bash scripts/trending.sh # Trending tokens |
Access to hidden dotfiles in home directory
| 320 | source ~/.openclaw/workspace/.env && bash scripts/analysis.sh # Full analysis dashboard |
Access to hidden dotfiles in home directory
| 321 | source ~/.openclaw/workspace/.env && python3 scripts/swap.py <mint> 0.1 # Buy |
Access to hidden dotfiles in home directory
| 322 | source ~/.openclaw/workspace/.env && python3 scripts/swap.py <mint> <amt> --sell # Sell |
Access to hidden dotfiles in home directory
| 323 | source ~/.openclaw/workspace/.env && bash scripts/test-api.sh # API connectivity test |
Access to .env file
| 39 | - filesystem:write:~/.openclaw/workspace/.env |
Access to .env file
| 50 | credential_file_read_note: "Only scripts/setup.py reads and writes ~/.openclaw/workspace/.env for initial keypair generation and address repair. All other scripts access credentials exclusively via pr |
Access to .env file
| 87 | 2. Add to `~/.openclaw/workspace/.env`: |
Access to .env file
| 89 | echo 'KRYPTOGO_API_KEY=sk_live_YOUR_KEY' >> ~/.openclaw/workspace/.env && chmod 600 ~/.openclaw/workspace/.env |
Access to .env file
| 92 | > **Do NOT paste your API key directly in chat.** Always set secrets via `.env` file. |
Access to .env file
| 100 | Creates a Solana keypair, saves to `.env` with chmod 600, prints public address to fund. |
Access to .env file
| 109 | - **NEVER** accept secrets pasted directly in chat — instruct users to set them in `.env` |
Access to .env file
| 110 | - **NEVER** use the Read tool on `.env` — load credentials via `source` command only |
Access to .env file
| 111 | - Runtime scripts do NOT read `.env` directly — all credentials are accessed via environment variables only, which must be pre-loaded by the caller (`source ~/.openclaw/workspace/.env`) |
Access to .env file
| 112 | - **Exception:** `scripts/setup.py` reads and writes `.env` for initial keypair generation and address repair — this is the only script that touches credential files |
Access to .env file
| 136 | source ~/.openclaw/workspace/.env |
Access to .env file
| 139 | This is REQUIRED — scripts do not read `.env` directly. All credentials are accessed via environment variables only. |
Access to .env file
| 188 | Runtime scripts in this skill do NOT read `.env` files directly. All credentials are accessed via environment variables only, which must be pre-loaded by the caller (`source ~/.openclaw/workspace/.env |
Access to .env file
| 190 | **Exception:** `scripts/setup.py` reads and writes `.env` — it loads existing keys to avoid regeneration, backs up `.env` before changes, and writes new keypair entries. This is the only script that t |
Access to .env file
| 200 | source ~/.openclaw/workspace/.env && bash scripts/cron-examples.sh setup-default |
Access to .env file
| 203 | source ~/.openclaw/workspace/.env && bash scripts/cron-examples.sh setup-autonomous |
Access to .env file
| 263 | source ~/.openclaw/workspace/.env && python3 scripts/swap.py <token_mint> 0.1 |
Access to .env file
| 264 | source ~/.openclaw/workspace/.env && python3 scripts/swap.py <token_mint> <amount> --sell |
Access to .env file
| 315 | All scripts require credentials to be pre-loaded: `source ~/.openclaw/workspace/.env` before running. |
Access to .env file
| 318 | source ~/.openclaw/workspace/.env && bash scripts/portfolio.sh # Portfolio check |
Access to .env file
| 319 | source ~/.openclaw/workspace/.env && bash scripts/trending.sh # Trending tokens |
Access to .env file
| 320 | source ~/.openclaw/workspace/.env && bash scripts/analysis.sh # Full analysis dashboard |
Access to .env file
| 321 | source ~/.openclaw/workspace/.env && python3 scripts/swap.py <mint> 0.1 # Buy |
Access to .env file
| 322 | source ~/.openclaw/workspace/.env && python3 scripts/swap.py <mint> <amt> --sell # Sell |
Access to .env file
| 323 | source ~/.openclaw/workspace/.env && bash scripts/test-api.sh # API connectivity test |
Access to .env file
| 371 | ├── .env.example |
External URL reference
| 7 | homepage: https://www.kryptogo.xyz |
External URL reference
| 10 | en: https://kryptogo.notion.site/Product-Guide-EN-26c3499de8a28179aafacb68304458ea |
External URL reference
| 11 | zh-tw: https://kryptogo.notion.site/kryptogo-xyz-usage-guide |
External URL reference
| 12 | zh-cn: https://kryptogo.notion.site/kryptogo-xyz-productguide-zhcn |
External URL reference
| 13 | whitepaper: https://wallet-static.kryptogo.com/public/whitepaper/kryptogo-xyz-whitepaper-v1.0.pdf |
External URL reference
| 24 | api_base: https://wallet-data.kryptogo.app |
External URL reference
| 86 | 1. Go to [kryptogo.xyz/account](https://www.kryptogo.xyz/account) and create an API key |
External URL reference
| 231 | > **Free tier limitation:** Cluster analysis only returns the top 2 clusters. To see full cluster data, upgrade at [kryptogo.xyz/pricing](https://www.kryptogo.xyz/pricing). |