raydium-plugin

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implementation follows security best practices for AI agent extensions, including integrity verification and clear documentation of trust boundaries.
  • [INDIRECT_PROMPT_INJECTION]: The skill explicitly addresses the risk of processing data from the Raydium API and Solana RPC. The SKILL.md file contains a dedicated 'Data Trust Boundary' section that instructs the agent to treat all CLI output as untrusted and to filter specific fields before processing, effectively mitigating potential injection attacks from external data sources.
  • [EXTERNAL_DOWNLOADS]: Pre-flight setup scripts download the onchainos CLI and the raydium-plugin binary from official GitHub repositories. These operations are performed over HTTPS and include strict SHA256 checksum verification to ensure the downloaded files have not been tampered with before they are executed or installed.
  • [COMMAND_EXECUTION]: The skill interacts with the local system through subprocess calls to the onchainos CLI for wallet management. These calls use fixed subcommands and program-controlled parameters, preventing arbitrary command injection.
  • [DATA_EXFILTRATION]: Network activity is strictly confined to expected functional endpoints: Raydium's REST APIs and the official Solana RPC node. No patterns suggestive of unauthorized data harvesting or secret exfiltration were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:05 PM