solanaprox-ai
仅含文档的 AI 技能,声明 14 种能力但 Security Manifest 仅声明 2 项权限,存在明显的文档-行为差异,缺少可验证的实际代码。
声明支持 14 种能力包括 code-execution(代码执行)、web-search、scraping 等敏感操作,但 Security Manifest 仅声明 Network 和 Env Read 两项权限,存在明显的声明-行为差异。
SKILL.md:97 Why this conclusion was reached
1/4 dimensions flaggedDeclared resources and inferred behavior are broadly aligned.
4 lower-risk artifacts were extracted and still need context.
The report includes 0 attack-chain steps and 1 severe findings.
Dependency information is incomplete, so supply-chain confidence stays limited.
What drove the risk score up
声明 14 种能力包括 code-execution/scraping,但 Security Manifest 仅声明 Network 和 Env Read
只有 SKILL.md,无脚本文件,无法验证实际行为
所有 API 调用指向外部域名 solanaprox.com,无开源代码
Most important evidence
敏感能力未在 Security Manifest 中声明
声明支持 14 种能力包括 code-execution(代码执行)、web-search、scraping 等敏感操作,但 Security Manifest 仅声明 Network 和 Env Read 两项权限,存在明显的声明-行为差异。
SKILL.md:97 外部服务依赖且无开源验证
所有功能实现依赖外部域名 solanaprox.com,缺少 GitHub 仓库或开源代码链接,无法验证实际行为与声明是否一致。
SKILL.md:8 Multi-Agent Orchestration 可能涉及更高权限操作
声称支持 agent-orchestration(代理编排),可能需要执行代码或访问文件系统,但未在声明中说明。
SKILL.md:88 钱包地址作为唯一凭证
使用 SOLANAPROX_WALLET_ADDRESS 作为唯一认证方式,可能被用于用户追踪。
SKILL.md:7 Declared capability vs actual capability
SKILL.md:Security Manifest SKILL.md:Security Manifest - SOLANAPROX_WALLET_ADDRESS SKILL.md:Capabilities list mentions web-search, scraping SKILL.md:Capabilities list mentions code-execution but not in Security Manifest Unknown - no script files to verify Suspicious artifacts and egress
https://solanaprox.com SKILL.md:8
https://solanaprox.com/v1/messages SKILL.md:57
https://solanaprox.com/api/orchestrate SKILL.md:92
https://solanaprox.com/api/capabilities SKILL.md:109
Dependencies and supply chain
There are no structured dependency warnings.
File composition
SKILL.md