kora-operator

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration techniques were detected in the skill instructions or scripts.
  • The skill provides comprehensive security guidance, explicitly warning operators about potential risks like fee-payer fund drainage and insecure pricing models.
  • It encourages best practices such as using HMAC authentication, reCAPTCHA, and restrictive fee-payer policies.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading official vendor tools and container images from well-known registries.
  • Refers to the official kora-cli tool via the Rust cargo package manager.
  • References Docker images hosted on the GitHub Container Registry (ghcr.io/solana-foundation/kora).
  • [COMMAND_EXECUTION]: The guide includes standard administrative and development commands necessary for the described use case.
  • Includes CLI commands for node operation, such as kora rpc start and kora config validate.
  • Mentions the use of a justfile for development tasks like building and running tests (just build, just unit-test).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 10:54 PM
Security Audit — agent-trust-hub — kora-operator