Back to skill

Security audit

Solana

Security checks for vulnerabilities and agentic risk

Overview

This Solana skill matches its stated wallet purpose, but it handles real mainnet funds with unsafe private-key storage and transaction-signing practices that require careful review.

Install only if you are comfortable using it with a dedicated low-value Solana wallet. Do not reuse a wallet holding important funds, avoid sourcing .env files, review every recipient, amount, mint, and network before running transaction commands, and prefer devnet or a hardware/managed wallet workflow where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/jup_swap.py:318
Finding

Remote API-Supplied Transaction Is Signed Without Instruction Validation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/initialize.py:25
Finding

Wallet Private Key Is Persisted in a Plaintext File Without Enforced Access Controls

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

Setup Documentation Instructs Users to Execute the Environment File as Shell Code

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Security-Critical Dependencies Are Unpinned and Lack Integrity Verification

Content
View full analysis
=0.34.0 solders>=0.21.0 base58>=2.1.0 python-dotenv>=1.0.0 aiohttp>=3.9.0 ``` ### Technical Analysis All dependencies use lower-bound constraints and therefore allow installation of arbitrary future versions. No lockfile or package hashes are provided. Installation at different times can consequently produce materially different executable code without any change to the audited project. These dependencies run inside processes that load the Solana private key, build and sign transactions, and communicate with external APIs. A compromised upstream release, malicious transitive dependency, or unsafe future update would execute in that sensitive context. No evidence was found that the currently named packages are typosquatted or intentionally malicious; the finding concerns the absence of version and integrity controls. ### Attack Path 1. An upstream package account, release process, distribution artifact, or transitive dependency is compromised, or a future release introduces unsafe behavior. 2. The user runs `pip install -r requirements.txt`. 3. The resolver selects the newer version because the requirement specifies only a minimum version. 4. Installation or import executes package-controlled code. 5. The dependency accesses process credentials, alters transaction construction, or changes network behavior. 6. Wallet credentials or signed transaction integrity may be compromised. ### Impact Assessment A malicious dependency executes with the same operating-system privileges as the Skill. It may access `SOLANA_PRIVATE_KEY`, `JUPITER_API_KEY`, local files, and network connectivity. In the worst case, this can lead to private-key disclosure, unauthorized transaction signing, wallet asset loss, or arbitrary local code execution. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (44)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The supplied code only covers a narrow subset of the declared functionality: Jupiter-based quoting and swapping, plus listing token metadata. It does not implement wallet creation, balance queries, SOL/token transfers, or Pump.fun token launches, all of which are explicitly claimed in the description. The primary purpose of this code chunk is swap operations via Jupiter Ultra API, using a private key and API key from environment variables to sign and execute transactions. That is consistent with part of the declaration ('swap via Jupiter') but not with the broader declared scope, so the description materially overstates what this code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a multi-capability Solana wallet skill, but the supplied code only handles Pump.fun token launching. It loads an existing private key from SOLANA_PRIVATE_KEY, uploads token assets/metadata to Pump.fun/IPFS endpoints, builds Pump.fun-specific create and optional buy instructions, and sends the transaction. There is no code for wallet creation, balance retrieval, SOL/token transfers, or Jupiter swaps. The Pump.fun launch portion matches part of the description, but the overall declared purpose materially overstates the implemented functionality, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code chunk is specifically a Solana wallet utility script for address lookup, SOL balance, token balance, SOL transfer, and SPL token transfer. Those parts align with part of the description. However, the declared purpose materially overstates the skill by including wallet creation, token swaps via Jupiter, and token launching on Pump.fun, none of which appear in this code. The trigger list also includes swap/jupiter/pumpfun terms that are unsupported by the supplied implementation. This is a description-behavior mismatch because significant declared capabilities are absent from the actual code.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The documentation instructs users to extract a private key from .env into an environment variable via shell command. While environment variables are common, this pattern normalizes direct handling of raw private keys in plaintext shell workflows, increasing exposure through shell history, process inspection, accidental logging, and downstream tool leakage.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

IMPORTANT: After running initialize.py, export the private key to your environment:

bash
export SOLANA_PRIVATE_KEY=$(grep SOLANA_PRIVATE_KEY .env | cut -d '=' -f2)

Or source the .env file:

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

Telling users to source .env can load secrets into the full shell session and any child processes, potentially exposing wallet private keys to unrelated commands, logs, debugging tools, or agent subprocesses. In a cryptocurrency skill, broad secret propagation is especially risky because compromise immediately enables fund theft.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

export SOLANA_PRIVATE_KEY=$(grep SOLANA_PRIVATE_KEY .env | cut -d '=' -f2)

text

Or source the .env file:
```bash
source .env

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The repeated .env secret-handling guidance reinforces unsafe credential practices for a blockchain private key. Because this secret authorizes irreversible on-chain actions, documentation that encourages casual plaintext handling materially increases the blast radius of any local compromise or accidental disclosure.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

Or source the .env file:

bash
source .env

Wallet Operations

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents mainnet transactions, swaps, token transfers, and token launches without prominent warnings about irreversible loss, scams, slippage, or wrong-address risk. In blockchain contexts, users may treat examples as safe defaults, so missing safety framing substantially raises the chance of real financial harm.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The script is explicitly designed to generate a Solana wallet and persist the private key in a plaintext .env file. Storing cryptocurrency private keys in an unencrypted local file materially increases the chance of credential theft through local compromise, accidental inclusion in source control, backups, logs, or unsafe shell workflows.

Content

Scanner excerpt · scripts/initialize.py (reported line 4)May include surrounding context.

python
#!/usr/bin/env python3
"""
Solana Wallet Initialization
Creates a new wallet and saves the private key to .env file
"""

import os

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

This function's purpose is to save a Solana private key into .env, which is not an appropriate storage mechanism for high-value cryptographic secrets. In a wallet-management skill, compromise of this file would directly allow theft of all assets controlled by the key.

Content

Scanner excerpt · scripts/initialize.py (reported line 27)May include surrounding context.

python
def save_to_env(private_key_base58: str, env_path: Path = None):
    """Save private key to .env file."""
    if env_path is None:
        env_path = Path.cwd() / ".env"

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

Defaulting secret storage to Path.cwd() / '.env' makes the private key land in the current working directory, which may be a project folder, shared workspace, synced directory, or repository root. That increases the probability of accidental exposure via commits, artifact collection, or other tooling that reads local config files.

Content

Scanner excerpt · scripts/initialize.py (reported line 29)May include surrounding context.

python
def save_to_env(private_key_base58: str, env_path: Path = None):
    """Save private key to .env file."""
    if env_path is None:
        env_path = Path.cwd() / ".env"
    
    env_content = {}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/initialize.py (reported line 33)May include surrounding context.

python
env_content = {}
    
    # Read existing .env if it exists
    if env_path.exists():
        with open(env_path, "r") as f:
            for line in f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/wallet.py (reported line 55)May include surrounding context.

python
env_content = {}
    
    # Read existing .env if it exists
    if env_path.exists():
        with open(env_path, "r") as f:
            for line in f:

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

Writing SOLANA_PRIVATE_KEY directly to a .env file creates a plaintext credential exposure path for the wallet's signing authority. For a cryptocurrency wallet, exposure of this secret is equivalent to full account takeover and likely irreversible asset loss.

Content

Scanner excerpt · scripts/initialize.py (reported line 45)May include surrounding context.

python
# Update or add SOLANA_PRIVATE_KEY
    env_content["SOLANA_PRIVATE_KEY"] = private_key_base58
    
    # Write back to .env
    with open(env_path, "w") as f:
        for key, value in env_content.items():
            f.write(f"{key}={value}\n")

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/initialize.py (reported line 58)May include surrounding context.

python
# Check if wallet already exists
    existing_key = os.environ.get("SOLANA_PRIVATE_KEY")
    env_path = Path.cwd() / ".env"
    
    if env_path.exists():
        with open(env_path, "r") as f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/initialize.py (reported line 64)May include surrounding context.

python
# Check if wallet already exists
    existing_key = os.environ.get("SOLANA_PRIVATE_KEY")
    env_path = Path.cwd() / ".env"
    
    if env_path.exists():
        with open(env_path, "r") as f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/initialize.py (reported line 96)May include surrounding context.

python
# Check if wallet already exists
    existing_key = os.environ.get("SOLANA_PRIVATE_KEY")
    env_path = Path.cwd() / ".env"
    
    if env_path.exists():
        with open(env_path, "r") as f:

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

This line participates in persisting the freshly generated private key to .env, reinforcing insecure plaintext storage of the full 64-byte secret. In the context of a Solana wallet skill, that makes the issue more dangerous because the secret immediately controls real fund transfers and token operations.

Content

Scanner excerpt · scripts/initialize.py (reported line 81)May include surrounding context.

python
private_key_bytes = bytes(keypair)
    private_key_base58 = base58.b58encode(private_key_bytes).decode("utf-8")
    
    # Save to .env
    saved_path = save_to_env(private_key_base58, env_path)
    
    print("✅ New wallet created!\n")

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The instructions encourage exporting the private key from .env into the shell environment, which broadens secret exposure to shell history, process environments, crash dumps, and subprocess inheritance. While not as severe as the original plaintext storage, it increases the attack surface for credential leakage.

Content

Scanner excerpt · scripts/initialize.py (reported line 92)May include surrounding context.

python
print()
    print("To use the wallet, export the private key to your environment:")
    print()
    print("  export SOLANA_PRIVATE_KEY=$(grep SOLANA_PRIVATE_KEY .env | cut -d '=' -f2)")
    print()
    print("Or source the .env file:")
    print()

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Telling users to source the .env file loads the wallet private key directly into the shell environment, potentially exposing it to subprocesses and operational mistakes. In a wallet skill, normalizing this pattern can lead to widespread insecure handling of high-value signing credentials.

Content

Scanner excerpt · scripts/initialize.py (reported line 94)May include surrounding context.

python
print()
    print("  export SOLANA_PRIVATE_KEY=$(grep SOLANA_PRIVATE_KEY .env | cut -d '=' -f2)")
    print()
    print("Or source the .env file:")
    print()
    print("  source .env")
    print()

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The script instructs users to extract and export a base58 private key from a local .env file into an environment variable, normalizing direct plaintext handling of the wallet secret. In an agent or multi-process environment, environment variables and shell history are often exposed to subprocesses, logs, crash dumps, or other users, increasing the chance of wallet compromise and total asset theft.

Content

Scanner excerpt · scripts/jup_swap.py (reported line 107)May include surrounding context.

python
print("Error: SOLANA_PRIVATE_KEY environment variable not set.")
        print("Run initialize.py first to create a wallet, then export the key:")
        print(
            "  export SOLANA_PRIVATE_KEY=$(grep SOLANA_PRIVATE_KEY .env | cut -d '=' -f2)")
        sys.exit(1)

    try:

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/pumpfun.py (reported line 223)May include surrounding context.

python
data.extend(bytes(user))  # creator pubkey
    data.append(1 if is_mayhem_mode else 0)  # is_mayhem_mode bool
    
    return Instruction(PUMP_PROGRAM_ID, bytes(data), accounts)


def create_ata_instruction(

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/pumpfun.py (reported line 243)May include surrounding context.

python
data.extend(bytes(user))  # creator pubkey
    data.append(1 if is_mayhem_mode else 0)  # is_mayhem_mode bool
    
    return Instruction(PUMP_PROGRAM_ID, bytes(data), accounts)


def create_ata_instruction(

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/pumpfun.py (reported line 283)May include surrounding context.

python
data.extend(bytes(user))  # creator pubkey
    data.append(1 if is_mayhem_mode else 0)  # is_mayhem_mode bool
    
    return Instruction(PUMP_PROGRAM_ID, bytes(data), accounts)


def create_ata_instruction(

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script constructs and broadcasts a live Solana mainnet transaction, including an optional dev buy that spends SOL, with no final confirmation prompt immediately before submission. Because the default network is mainnet and preflight is skipped, a user can unintentionally spend funds or launch a token irreversibly with minimal friction and reduced safety checks.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares access to sensitive capabilities through its documented behavior—environment secrets, file reads/writes, and networked blockchain actions—but does not constrain them with explicit tool scoping. In an agent setting, missing scope boundaries increases the chance of unintended secret exposure, arbitrary file modification, or unreviewed transaction/network actions beyond the user's intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.