solana-kit

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE]: The skill includes instructional code in 'references/features-keypairs.md' that demonstrates how to read a Solana private key from the local filesystem.
  • Evidence: The documentation provides an example using fs.readFileSync('~/.config/solana/id.json') to load a keypair. While this is a standard developer practice for the Solana CLI ecosystem, it involves access to a highly sensitive file path containing private credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted sources on the Solana blockchain.
  • Ingestion points: Data enters the agent's context through RPC methods such as rpc.getAccountInfo, rpc.getTransaction, and WebSocket subscriptions via rpcSubscriptions.accountNotifications (documented in 'references/core-rpc.md' and 'references/core-rpc-subscriptions.md').
  • Boundary markers: There are no specific instructions or boundary markers provided to ensure that data fetched from the blockchain is treated as untrusted or to prevent the agent from executing instructions embedded in that data.
  • Capability inventory: The skill allows the agent to perform sensitive operations including building, signing, and sending transactions via signTransactionMessageWithSigners and sendAndConfirmTransaction (documented in 'references/core-transactions.md').
  • Sanitization: The instructions do not specify any sanitization, validation, or escaping logic for data retrieved from the blockchain before it is used in subsequent agent actions or prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 03:58 AM