helius-jupiter

Warn

Audited by Snyk on Aug 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The skill includes a runtime script import that will fetch and execute remote JavaScript from https://plugin.jup.ag/plugin-v1.js (e.g., the and dynamic import of the Jupiter plugin), which is a runtime-executed external dependency used by the widget flow.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed to execute on-chain financial operations. It documents Jupiter Swap, Lend, Trigger (limit orders), Recurring (DCA), Perps, and instructs using Helius Sender for transaction submission (including raw tx submission, priority-fee guidance, and SDK write functions like getDepositIxs/getWithdrawIxs/getOperateIx). These are concrete APIs and functions whose primary purpose is to move funds or place market/order transactions on Solana.

Issues (2)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 03:57 PM
Issues
2
Security Audit — snyk — helius-jupiter