solana-agent-kit

Warn

Audited by Socket on Aug 4, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
examples/autonomous-agent/README.md

No clear indicators of classic malicious code (obfuscation, backdoors, eval/Function-based payloads, suspicious exfiltration, or system tampering) are present in the provided fragment. However, the module is inherently high security risk because it loads a real Solana private key, enables LLM-driven autonomous/event-triggered on-chain actions via Solana tools, and the safety guardrails shown appear not to be enforced in the primary execution flows. The likely risk is unintended or attacker-influenced financial actions (e.g., prompt/trigger-driven trades), rather than covert malware.

Confidence: 62%Severity: 78%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and uses mostly verifiable same-org npm packages, but it teaches an AI agent to perform autonomous blockchain transactions with direct private-key access. The main concern is high-impact financial autonomy and credential forwarding to external CLI/MCP tooling, not confirmed malware or deceptive exfiltration.

Confidence: 87%Severity: 81%
Audit Metadata
Analyzed At
Aug 4, 2026, 12:39 AM
Package URL
pkg:socket/skills-sh/JustaName-id%2Fcryptoskills%2Fsolana-agent-kit%2F@1add491178db1fecb68e26d44f36162815ca387e2b665c5fbed37f57bdcaf1a4
Security Audit — socket — solana-agent-kit