helius-jupiter

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches market data and transaction parameters from official ecosystem endpoints including Jupiter's aggregation APIs (api.jup.ag) and Jito's MEV infrastructure (bundles.jito.wtf).
  • [EXTERNAL_DOWNLOADS]: References standard Node.js libraries for Solana development such as @solana/web3.js, helius-sdk, and @jup-ag/lend for transaction construction and data processing.
  • [PROMPT_INJECTION]: Documents the attack surface for indirect prompt injection inherent in processing external API data for decentralized finance operations. The skill includes specific mitigation rules, such as using Jupiter's Token Shield and mandatory validation of mint addresses and wallet ownership.
  • [DATA_EXFILTRATION]: No suspicious network activity or sensitive data exfiltration detected. The skill adheres to best practices by recommending environment variables for API key management and utilizing local transaction signing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — helius-jupiter