solana-agent-kit

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill is coherent with its stated purpose and appears to reference the official Solana Agent Kit npm ecosystem, so it is not malware. However, it is a high-risk skill because its intended function is to give an AI agent autonomous control over cryptocurrency actions using wallet credentials, including trading and transfers. Risk comes from scope and real-world financial autonomy, not from deceptive data exfiltration.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
Mar 18, 2026, 01:43 AM
Package URL
pkg:socket/skills-sh/sendaifun%2Fskills%2Fsolana-agent-kit%2F@b4d10ad0c97a0cae25e7a2ecb8231e4e9c59b17d
Security Audit — socket — solana-agent-kit