helius-phantom

Fail

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: CRITICAL
Full Analysis
  • [SAFE]: The skill provides integration guidance and code templates for the official Phantom Connect SDKs and Helius infrastructure, adhering to standard development practices.
  • [SAFE]: All network operations documented in the code samples target well-known and trusted technology services in the Solana ecosystem, including Helius RPC nodes, Jito tip floors, and CoinGecko price APIs.
  • [SAFE]: The instructions explicitly enforce security measures to prevent API key exposure in client-side code, providing robust examples of Next.js, Express, and Cloudflare Worker proxy patterns.
  • [SAFE]: The skill uses standard base64 encoding and decoding for Solana transaction serialization (via atob and btoa), which is a necessary and routine operation for blockchain transaction handling.
  • [SAFE]: External dependencies are sourced from established package registries (NPM) and relate directly to the skill's primary purpose of blockchain development.
  • [SAFE]: The skill mentions sensitive file paths such as ~/.helius-cli/keypair.json, but only in the context of official tool configuration and user-initiated account setup, posing no risk of unauthorized access.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — helius-phantom