phantom-connect

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of documentation and code snippets for integrating Phantom's official SDKs. All analyzed content is consistent with legitimate developer documentation.
  • [DATA_EXFILTRATION]: No unauthorized data exfiltration patterns were detected. The skill's network interactions are restricted to official blockchain infrastructure (Solana RPC), decentralized storage (Arweave), and well-known financial APIs (CoinGecko).
  • [CREDENTIALS_UNSAFE]: The skill demonstrates safe credential handling by explicitly instructing developers to avoid hardcoding secrets and instead use environment variables for sensitive data like private keys and API IDs.
  • [REMOTE_CODE_EXECUTION]: No suspicious remote code execution or untrusted dependency downloads were observed. The featured packages and initialization scripts belong to official and recognized projects within the Solana ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 08:38 AM
Security Audit — agent-trust-hub — phantom-connect