helius
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The instructions direct users to install Helius tools using
npx, which fetches packages (helius-mcp,helius-cli) from the official npm registry. - [COMMAND_EXECUTION]: The skill provides various CLI commands for local environment setup, including keypair generation and account management via the Helius CLI.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and display untrusted data from the Solana blockchain, such as NFT metadata, transaction descriptions, and event logs.
- Ingestion points: Data enters the context via
parseTransactions,getAssetsByOwner, andgetWalletHistory(found inreferences/enhanced-transactions.md,references/das.md, andreferences/wallet-api.md). - Boundary markers: The instructions do not explicitly specify boundary markers for blockchain data.
- Capability inventory: The skill includes tools for asset transfers (
transferSol,transferToken), webhook management, and subscription setup. - Sanitization: Standard SDK parsing is used, but the skill assumes the AI will handle the human-readable descriptions safely.
- [SAFE]: The skill follows security best practices by explicitly warning against hardcoding API keys in source code and recommending the use of environment variables. All external references point to official Helius infrastructure and well-known Solana development tools.
Audit Metadata