helius-phantom
Fail
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: CRITICAL
Full Analysis
- [SAFE]: The skill provides integration guidance and code templates for the official Phantom Connect SDKs and Helius infrastructure, adhering to standard development practices.
- [SAFE]: All network operations documented in the code samples target well-known and trusted technology services in the Solana ecosystem, including Helius RPC nodes, Jito tip floors, and CoinGecko price APIs.
- [SAFE]: The instructions explicitly enforce security measures to prevent API key exposure in client-side code, providing robust examples of Next.js, Express, and Cloudflare Worker proxy patterns.
- [SAFE]: The skill uses standard base64 encoding and decoding for Solana transaction serialization (via
atobandbtoa), which is a necessary and routine operation for blockchain transaction handling. - [SAFE]: External dependencies are sourced from established package registries (NPM) and relate directly to the skill's primary purpose of blockchain development.
- [SAFE]: The skill mentions sensitive file paths such as
~/.helius-cli/keypair.json, but only in the context of official tool configuration and user-initiated account setup, posing no risk of unauthorized access.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata