helius

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The instructions direct users to install Helius tools using npx, which fetches packages (helius-mcp, helius-cli) from the official npm registry.
  • [COMMAND_EXECUTION]: The skill provides various CLI commands for local environment setup, including keypair generation and account management via the Helius CLI.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and display untrusted data from the Solana blockchain, such as NFT metadata, transaction descriptions, and event logs.
  • Ingestion points: Data enters the context via parseTransactions, getAssetsByOwner, and getWalletHistory (found in references/enhanced-transactions.md, references/das.md, and references/wallet-api.md).
  • Boundary markers: The instructions do not explicitly specify boundary markers for blockchain data.
  • Capability inventory: The skill includes tools for asset transfers (transferSol, transferToken), webhook management, and subscription setup.
  • Sanitization: Standard SDK parsing is used, but the skill assumes the AI will handle the human-readable descriptions safely.
  • [SAFE]: The skill follows security best practices by explicitly warning against hardcoding API keys in source code and recommending the use of environment variables. All external references point to official Helius infrastructure and well-known Solana development tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:56 PM
Security Audit — agent-trust-hub — helius