raydium-plugin
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implementation follows security best practices for AI agent extensions, including integrity verification and clear documentation of trust boundaries.
- [INDIRECT_PROMPT_INJECTION]: The skill explicitly addresses the risk of processing data from the Raydium API and Solana RPC. The
SKILL.mdfile contains a dedicated 'Data Trust Boundary' section that instructs the agent to treat all CLI output as untrusted and to filter specific fields before processing, effectively mitigating potential injection attacks from external data sources. - [EXTERNAL_DOWNLOADS]: Pre-flight setup scripts download the
onchainosCLI and theraydium-pluginbinary from official GitHub repositories. These operations are performed over HTTPS and include strict SHA256 checksum verification to ensure the downloaded files have not been tampered with before they are executed or installed. - [COMMAND_EXECUTION]: The skill interacts with the local system through subprocess calls to the
onchainosCLI for wallet management. These calls use fixed subcommands and program-controlled parameters, preventing arbitrary command injection. - [DATA_EXFILTRATION]: Network activity is strictly confined to expected functional endpoints: Raydium's REST APIs and the official Solana RPC node. No patterns suggestive of unauthorized data harvesting or secret exfiltration were found.
Audit Metadata