skills/sarthib7/agentsmith/solana-dev/Gen Agent Trust Hub

solana-dev

Fail

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the user to install the Surfpool testing utility using a piped shell execution pattern from remote URLs (run.surfpool.run and github.com/txtx/surfpool). This is a high-risk pattern that executes remote scripts directly without integrity verification.
  • [COMMAND_EXECUTION]: The skill includes instructions to install an external Model Context Protocol (MCP) server from mcp.solana.com using the claude mcp add command, which dynamically expands the agent's available tools from a remote source.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface through the ingestion of untrusted on-chain data, RPC responses, and program logs. Ingestion points include account data and log streams (SKILL.md, accounts.md). While it instructs the agent to treat this data as untrusted and validate it, the lack of programmatic boundary markers remains a vulnerability. Additionally, the skill metadata deceptively claims authorship by 'Solana Foundation' when the actual author is 'Sarthib7'.
  • [NO_CODE]: No executable code, binaries, or scripts are included within the skill package; its functionality relies entirely on documentation and instructions for external tool usage.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 1, 2026, 11:05 AM
Security Audit — agent-trust-hub — solana-dev