solana-dev

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install essential Solana development tools (Solana CLI, Surfpool) from official project domains such as release.anza.xyz and run.surfpool.run.
  • [REMOTE_CODE_EXECUTION]: Documentation includes standard installation procedures involving piping remote scripts to the shell. These scripts are sourced from established and trusted ecosystem providers.
  • [COMMAND_EXECUTION]: The skill instructs the agent to run various development-related CLI tools like anchor, solana, and surfpool to build, test, and deploy blockchain programs. It also includes commands for managing local development processes like pkill.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements robust defenses by instructing the agent to treat all on-chain data (accounts, logs, RPC responses) as untrusted input and to explicitly ignore any directives embedded within them, following guardrail W011.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 07:43 PM
Security Audit — agent-trust-hub — solana-dev