helius-jupiter

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation, architectural patterns, and code examples for building legitimate DeFi applications on the Solana blockchain using Helius and Jupiter services.
  • [COMMAND_EXECUTION]: The install.sh script is a standard installer that performs local file operations, such as creating directories and copying skill files to the user's local environment. It does not perform any unauthorized system modifications or execute remote scripts.
  • [EXTERNAL_DOWNLOADS]: The skill references official API endpoints and repositories belonging to Helius Labs and Jupiter. These references are essential for the skill's functionality and are sourced from the author's own infrastructure or established, well-known services in the Solana ecosystem.
  • [PROMPT_INJECTION]: The instructions in SKILL.md include explicit guardrails for the agent, such as requiring the presence of Helius MCP tools and forbidding workarounds via curl if tools are missing. There are no attempts to override the agent's safety protocols or instructions to ignore previous rules.
  • [CREDENTIALS_UNSAFE]: The documentation correctly advises users to use environment variables for API keys and provides tools for secure key management, avoiding hardcoded secrets within the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 02:47 AM