solana-agent-kit
Audited by Socket on Aug 4, 2026
2 alerts found:
Securityx2No clear indicators of classic malicious code (obfuscation, backdoors, eval/Function-based payloads, suspicious exfiltration, or system tampering) are present in the provided fragment. However, the module is inherently high security risk because it loads a real Solana private key, enables LLM-driven autonomous/event-triggered on-chain actions via Solana tools, and the safety guardrails shown appear not to be enforced in the primary execution flows. The likely risk is unintended or attacker-influenced financial actions (e.g., prompt/trigger-driven trades), rather than covert malware.
SUSPICIOUS: the skill is purpose-aligned and uses mostly verifiable same-org npm packages, but it teaches an AI agent to perform autonomous blockchain transactions with direct private-key access. The main concern is high-impact financial autonomy and credential forwarding to external CLI/MCP tooling, not confirmed malware or deceptive exfiltration.