helius-phantom

Warn

Audited by Snyk on Aug 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In Pattern 3 (Real-Time Dashboard), the runtime path connects the server relay to Helius WebSockets and then relays incoming transactionNotification/accountNotification fields (including logMessages/transaction details) to the client via SSE, meaning any outsider-authored on-chain content that reaches those notifications is ingested as free text at runtime.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly defines crypto transaction signing and submission flows: Phantom wallet signing (signTransaction / signAndSendTransaction), submitting signed transactions via Helius Sender (including the HTTPS Sender endpoint), transferring SOL/SPL tokens, and accepting crypto payments (SOL/USDC) with backend verification. It lists Helius Sender-related MCP tools (e.g., getSenderInfo, getPriorityFeeEstimate) and prescribes transaction sending settings—i.e., it is specifically designed to move crypto funds.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 03:57 PM
Issues
2
Security Audit — snyk — helius-phantom