skills/sendaifun/skills/switchboard/Gen Agent Trust Hub

switchboard

Fail

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE] (HIGH): Several scripts, including examples/setup/example.ts, examples/feeds/pull-feed.ts, and examples/feeds/oracle-quote.ts, implement a loadWallet function that reads the user's Solana private key from ~/.config/solana/id.json using fs.readFileSync. Direct access to sensitive credential files is a high-risk pattern.
  • [EXTERNAL_DOWNLOADS] (MEDIUM): Documentation in resources/github-repos.md and code imports reference packages from the @switchboard-xyz and @coral-xyz namespaces, and suggest cloning from the switchboard-xyz GitHub organization. As these sources are not in the predefined trusted list, they represent unverifiable external dependencies.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 19, 2026, 12:51 AM