jupiter
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a developer guide for integrating official Helius and Jupiter services on the Solana blockchain. All documented network operations target official vendor domains, specifically
helius-rpc.com,jup.ag, andhelius.xyz.- [SAFE]: References to sensitive file paths, such as~/.helius-cli/keypair.json, are associated with the standard configuration and legitimate operations of the Helius CLI and MCP tools for wallet management and transaction signing.- [SAFE]: The skill describes processing external data from blockchain APIs. While this creates a surface for indirect prompt injection, the risk is mitigated by instructions guiding developers to use security tools like the Jupiter Token Shield API to verify the legitimacy of assets and metadata.- [SAFE]: External dependencies and script references, including the Jupiter Plugin and various Node.js SDKs, are official packages from trusted vendors used for standard blockchain development. The use ofnpx helius-mcp@latestis documented for setting up the vendor's own MCP server environment.
Audit Metadata