solana-kit
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXPOSURE]: The skill includes instructional code in 'references/features-keypairs.md' that demonstrates how to read a Solana private key from the local filesystem.
- Evidence: The documentation provides an example using
fs.readFileSync('~/.config/solana/id.json')to load a keypair. While this is a standard developer practice for the Solana CLI ecosystem, it involves access to a highly sensitive file path containing private credentials. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted sources on the Solana blockchain.
- Ingestion points: Data enters the agent's context through RPC methods such as
rpc.getAccountInfo,rpc.getTransaction, and WebSocket subscriptions viarpcSubscriptions.accountNotifications(documented in 'references/core-rpc.md' and 'references/core-rpc-subscriptions.md'). - Boundary markers: There are no specific instructions or boundary markers provided to ensure that data fetched from the blockchain is treated as untrusted or to prevent the agent from executing instructions embedded in that data.
- Capability inventory: The skill allows the agent to perform sensitive operations including building, signing, and sending transactions via
signTransactionMessageWithSignersandsendAndConfirmTransaction(documented in 'references/core-transactions.md'). - Sanitization: The instructions do not specify any sanitization, validation, or escaping logic for data retrieved from the blockchain before it is used in subsequent agent actions or prompts.
Audit Metadata