svm

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows best practices by using restricted MCP tools to fetch data from established, authoritative sources such as the Helius blog and Solana's official GitHub repositories (Agave, Firedancer). It explicitly instructs the agent not to write files and to cite sources for all answers.
  • [EXTERNAL_DOWNLOADS]: The skill provides a setup instruction for the user to install the helius-mcp package via npx. This is a standard dependency for the skill's functionality and targets a well-known service provider in the Solana ecosystem.
  • [DATA_EXFILTRATION]: There is no evidence of data exfiltration. The skill interacts with public knowledge bases and does not access sensitive local directories, environment variables, or user credentials.
  • [PROMPT_INJECTION]: No prompt injection patterns were detected. The instructions are purely functional, guiding the agent on how to use provided tools to answer architectural questions without attempting to bypass safety filters or override core behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — svm