solana-development

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install core Solana development tools and frameworks from official and well-known repositories, including the Solana toolchain installer and the Anchor framework.
  • [COMMAND_EXECUTION]: Instructions include standard development commands using cargo, anchor, npm, and the solana CLI to initialize projects, build programs, and run tests.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is auditing and testing Solana programs, which involves the ingestion of user-provided code files. This presents a surface for indirect prompt injection if the audited code contains malicious instructions targeting the agent.
  • Ingestion points: Program source files (.rs), configuration files (Cargo.toml, Anchor.toml), and client scripts (.js, .ts) provided by the user (as referenced in SKILL.md and references/testing-practices.md).
  • Boundary markers: The skill mitigates this risk by providing extensive security checklists and validation patterns designed to identify and isolate malicious logic during the auditing process.
  • Capability inventory: Compilation and testing capabilities provided via cargo, anchor, and npm CLI tools (referenced in references/anchor.md and references/testing-frameworks.md).
  • Sanitization: The skill relies on structured security review processes and specific vulnerability detection patterns to distinguish between executable code and potential injection attempts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:05 PM
Security Audit — agent-trust-hub — solana-development