jupiter

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the Jupiter API (lite-api.jup.ag) and Solana RPC endpoints, creating a potential surface for indirect prompt injection.
  • Ingestion points: External data enters via jupiter_swap, jupiter_price, and jupiter_limit_orders in exports.py.
  • Boundary markers: The SKILL.md instructions explicitly require the agent to present all trade details to the user and obtain manual confirmation before proceeding to sign or broadcast transactions.
  • Capability inventory: The skill uses jupiter_execute_swap and jupiter_broadcast_tx to interact with the Solana blockchain.
  • Sanitization: Data from external APIs is formatted for display but does not undergo specific content filtering for natural language instructions.
  • [DATA_EXPOSURE]: The _trade_report.py module transmits trade metadata (wallet addresses, symbols, and transaction hashes) to a vendor-controlled endpoint specified by the AI_AGENT_API_URL environment variable. This telemetry is an integrated feature of the skill authored by starchild-ai-agent and uses a platform-issued CONTAINER_JWT for authentication.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — jupiter