helius-phantom
Warn
Audited by Snyk on Aug 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In Pattern 3 (Real-Time Dashboard), the runtime path connects the server relay to Helius WebSockets and then relays incoming
transactionNotification/accountNotificationfields (includinglogMessages/transaction details) to the client via SSE, meaning any outsider-authored on-chain content that reaches those notifications is ingested as free text at runtime.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly defines crypto transaction signing and submission flows: Phantom wallet signing (signTransaction / signAndSendTransaction), submitting signed transactions via Helius Sender (including the HTTPS Sender endpoint), transferring SOL/SPL tokens, and accepting crypto payments (SOL/USDC) with backend verification. It lists Helius Sender-related MCP tools (e.g., getSenderInfo, getPriorityFeeEstimate) and prescribes transaction sending settings—i.e., it is specifically designed to move crypto funds.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata