Solana Agent KitCAUTION
connect any ai agents to solana protocols
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[!TIP] checkout Suzi 🌸 by SendAI
[](https://www.npmjs.com/package/solana-agent-kit) [](https://github.com/sendaifun/solana-agent-kit/network/members) [](https://github.com/sendaifun/solana-agent-kit/blob/v2/LICENSE)
An open-source toolkit for connecting AI agents to Solana protocols. Now, any agent, using any model can autonomously perform 60+ Solana actions:
- Trade tokens
- Launch new tokens
- Lend assets
- Send compressed airdrops
- Execute blinks
- Launch tokens on AMMs
- Bridge tokens across chains
- And more...
Anyone - whether an SF-based AI researcher or a crypto-native builder - can bring their AI agents trained with any model and seamlessly integrate with Solana.
[](https://replit.com/@sendaifun/Solana-Agent-Kit)
Replit template created by Arpit Singh
🔧 Core Blockchain Features
- Token Operations
- Deploy SPL tokens by Metaplex
- Transfer assets
- Balance checks
- Stake SOL
- Zk compressed Airdrop by Light Protocol and Helius
- Bridge tokens across chains using Wormhole
- NFTs on 3.Land
- Create your own collection
- NFT creation and automatic listing on 3.land
- List your NFT for sale in any SPL token
- NFT Management via Metaplex
- Collection deployment
- NFT minting
- Metadata management
- Royalty configuration
- DeFi Integration
- Jupiter Exchange swaps
- Launch on Pump via PumpPortal
- Raydium pool creation (CPMM, CLMM, AMMv4)
- Orca
6fef39b5e832OBSERVED · 2026-09-23Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add integration-test --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env DISCORD_BOT_TOKEN=${DISCORD_BOT_TOKEN} --env FLEXLEND_API_KEY=${FLEXLEND_API_KEY} --env HELIUS_API_KEY=${HELIUS_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"integration-test": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"DISCORD_BOT_TOKEN": "${DISCORD_BOT_TOKEN}",
"FLEXLEND_API_KEY": "${FLEXLEND_API_KEY}",
"HELIUS_API_KEY": "${HELIUS_API_KEY}"
}
}
}
}Exposed tools (69)
61 read · 8 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
AVAILABLE_DRIFT_MARKETS | read | Get a list of available drift markets |
BID_ON_MAGICEDEN_NFT | read | Place a bid on an NFT listed on MagicEden |
CLAIM_PARA_PREGEN_WALLET | read | Claim a pregen wallet for Para |
CREATE_METEORA_DLMM_POOL | write | Create a new Meteora DLMM pool |
CREATE_METEORA_DYNAMIC_AMM_POOL | write | Create a new dynamic AMM pool on Meteora |
CREATE_ORCA_CLMM_ACTION | write | Create a Concentrated Liquidity Market Maker (CLMM) pool on Orca, the most efficient and capital-optimized CLMM on Solana. This function initializes a CLMM pool but does not add liquidity. You can add liquidity later using a centered position or a single-sided position. |
DEBRIDGE_CREATE_BRIDGE_ORDER | write | Create a cross-chain bridge order using deBridge to transfer tokens between chains. Returns both the transaction data and estimated amounts. |
DEBRIDGE_EXECUTE_BRIDGE_ORDER | write | Execute a cross-chain bridge transaction on Solana using deBridge with the transaction data from DEBRIDGE_CREATE_BRIDGE_ORDER. |
DEBRIDGE_GET_SUPPORTED_CHAINS | read | Fetch the list of chains supported by deBridge for cross-chain token transfers |
DEBRIDGE_GET_TOKENS_INFO | read | Get information about tokens available for cross-chain bridging via deBridge protocol. First use DEBRIDGE_GET_SUPPORTED_CHAINS to get the list of valid chain IDs, then provide the chain ID from that list. For EVM chains: use 0x-prefixed address. For Solana: use base58 token address. |
DEPOSIT_INTO_DRIFT_VAULT | read | Deposit funds into an existing drift vault |
DEPOSIT_TO_DRIFT_USER_ACCOUNT | read | Deposit funds into your drift user account |
DOES_USER_HAVE_DRIFT_ACCOUNT | read | Check if a user has a Drift account |
DRIFT_GET_ENTRY_QUOTE_OF_PERP_TRADE_ACTION | read | Get the entry quote of a perpetual trade on Drift |
DRIFT_GET_LEND_AND_BORROW_APY_ACTION | read | Get the lending and borrowing APY (in %) of a token on Drift |
DRIFT_PERP_MARKET_FUNDING_RATE_ACTION | read | Get the funding rate of a perpetual market on Drift |
DRIFT_SPOT_TOKEN_SWAP_ACTION | read | Swap a token for another token on Drift |
FETCH_ORCA_POSITIONS_ACTION | read | Fetch all the liquidity positions in an Orca Whirlpool by owner. Returns an object with position mint addresses as keys and position status details as values. |
GET_ALL_WALLETS | read | Get all wallets |
GET_COINGECKO_LATEST_POOLS | read | Get the latest pools on Coingecko |
GET_COINGECKO_TOKEN_INFO_ACTION | read | Get token information from Coingecko |
GET_COINGECKO_TOKEN_PRICE_DATA_ACTION | read | Get the price data of a token on Coingecko |
GET_COINGECKO_TOP_GAINERS | read | Get the top gainers on Coingecko |
GET_COINGECKO_TRENDING_POOLS_ACTION | read | Get the trending pools on Coingecko |
GET_COINGECKO_TRENDING_TOKENS_ACTION | read | Get the trending tokens on Coingecko |
GET_MAGICEDEN_COLLECTION_LISTINGS | read | Fetch listings for a specific NFT collection on MagicEden |
GET_MAGICEDEN_COLLECTION_STATS | read | Fetch statistics for a specific NFT collection on MagicEden |
GET_POPULAR_MAGICEDEN_COLLECTIONS | read | Fetch popular NFT collections from MagicEden |
HOMOMEMETUS_FETCH_OLDEST_TOKEN | read | Oldest token list from token list created in 24h |
HOMOMEMETUS_FETCH_RECENT_TOKEN | read | Recent token list from token list created in 24h |
HOMOMEMETUS_FETCH_TOKENS_BY_CREATORS | read | Creator-address-list-based token filter |
HOMOMEMETUS_FETCH_TOKENS_BY_DURATION | read | Creation-time-based token filter |
HOMOMEMETUS_FETCH_TOKENS_BY_INITIALIZER | read | Initializer-address-list-based token filter |
HOMOMEMETUS_FETCH_TOKENS_BY_MARKET_CAP | read | Market-cap-based token filter |
HOMOMEMETUS_FETCH_TOKENS_BY_METADATA | read | Metadata-based token filter |
HOMOMEMETUS_FETCH_TOKENS_BY_MINTS | read | Mint-addresses-based token filter |
HOMOMEMETUS_FETCH_TOKEN_BY_CREATOR | read | Creator-address-based token filter |
HOMOMEMETUS_FETCH_TOKEN_BY_INITIALIZER | read | Initializer-address-based token filter |
HOMOMEMETUS_FETCH_TOKEN_BY_MINT | read | Mint-address-based token filter |
HOMOMEMETUS_FETCH_TOKEN_BY_SIGNATURE | read | Creation-signature-based token filter |
LIST_MAGICEDEN_NFT | read | List an NFT for sale on MagicEden |
OKX_EXECUTE_SWAP | write | Execute swap through okx dex |
OKX_GET_CHAIN_DATA | read | Get Chain data from okx dex |
OKX_GET_LIQUIDITY | read | Get liquidity data from okx dex |
OKX_GET_QUOTE | read | Get quote data from okx dex |
OKX_GET_SWAP_DATA | read | Get swap instruction data from okx dex |
OKX_GET_TOKEN | read | Get token data from okx dex |
OPEN_ORCA_CENTERED_POSITION_WITH_LIQUIDITY_ACTION | read | Open a new Orca whirlpool position with liquidity centered around the current price. This function opens a new liquidity position in an Orca whirlpool with the provided liquidity amount centered around the current price. |
OPEN_ORCA_SINGLE_SIDED_POSITION_ACTION | read | Open a single-sided liquidity position in an Orca Whirlpool |
OSEC_CREATE_VERIFICATION_PDA | write | Generate a PDA for program verification and verify the program using Otter Sec |
OSEC_DECODE_VERIFICATION_PDA_DATA | read | Decode the PDA data composed in hex. |
OSEC_GET_PROGRAM_BUILD_LOG | read | Get program build for a solana program |
OSEC_GET_PROGRAM_VERIFICATION_STATUS | read | Get program verification status |
OSEC_GET_VERIFICATION_JOB_STATUS | read | Get status of an async verification job |
OSEC_GET_VERIFIED_PROGRAM | read | Get list of all verified programs |
OSEC_VERIFY_PROGRAM | read | Verify a Solana program |
REQUEST_UNSTAKE_FROM_DRIFT_INSURANCE_FUND_ACTION | read | Request to unstake a certain amount of a token from the Drift Insurance Fund |
REQUEST_WITHDRAWAL_FROM_DRIFT_VAULT | read | Request a withdrawal from an existing drift vault |
RUGCHECK | read | Check if a token is a rug pull |
SOLUTIOFI_BURN_TOKENS | read | Burn tokens using SolutioFi |
SOLUTIOFI_CLOSE_ACCOUNTS | read | Close specific token accounts using SolutioFi |
SOLUTIOFI_MERGE_TOKENS | write | Merge multiple tokens into one using SolutioFi |
SOLUTIOFI_SPREAD_TOKEN | read | Split a token into multiple tokens using SolutioFi |
STAKE_TO_DRIFT_INSURANCE_FUND_ACTION | read | Stake a token to Drift Insurance Fund |
UNSTAKE_FROM_DRIFT_INSURANCE_FUND_ACTION | read | Unstake requested unstake token from the Drift Insurance fund once the cool period has elapsed |
USE_WALLET | read | Use a wallet |
WITHDRAW_FROM_DRIFT_VAULT | read | Withdraw funds from a vault given the redemption time has elapsed. |
WITHDRAW_OR_BORROW_FROM_DRIFT_ACCOUNT | read | Withdraw funds from your drift account |
search_state_of_union | read | Searches and returns documents regarding the state-of-the-union. |
Trust audit
CAUTIONgrade F · trust 60/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
"0x23b872dd000000000000000000000000742d35cc6634c0532925a3b844bc454e4438f44e000000000000000000000000e7351fd770a37282b91d153ee690b63579b6e837000000000000000000000000000000000000000000000000000de0b6b3a76
data: "3UfFcAn6toX6QG3XuYGFA24PKaK4o62QKQQTD4fBR1U7nKPurhPBnLWXZsAymchhkAM9kHJKM3moahBMR9sJUmGHdL59gxq6PXidgJ5e7FUuePqzCRyutowo5qXSGARUpuJ46eMcXG2SgFo3pHx1bi3WHnJMydkj3UfEJcmRQrKyzYQGeAP9njjB1QbRcUudt
"FGluY2x1ZGVfY29udGV4dF91dWlkDnF1ZXJ5VGhlbkZldGNoAxZBNTBtYmVEM1RUR2NycUdHUE9GMnN3AAAAAABm5oUWVERUVURyRHFRZ2VYY1F0cVh1UWloZxZMdjdsV2N5TVMzLU9LZkNFOWVWVlBBAAAAAAA25W0WWXBqUmN2eXlUNUdjakhFOGZ5XzZ5ZxZaZGp
hex: "ce65c2888771730ca28e257dae8c81dc8ce27c9cc2451fb1837c52039847481f5b65cc6f152573c3efae07731701872e5391cb1a51627c845f1e12e9754d110f87751ac868003b5f05000000302e342e383300000068747470733a2f2f67697468
"3UwpeiMtquiTRwEh3LDXQ2ackEUawDAPVnEmbcfFU66N4Knmo4ArVS1XPSjj5UvUtsdQSxGcksSP5ERNDR36DFz8VnkSNBBFt5LfGc3WV7nDpqSfrcguxcMSgE7it74MGBBXUix9tPdKxxete8o4DKEUyt4b6mWnR9DbnyiNL8JnhAddSh99YP8zXGAFboUYejp5sVo
password: "ChangeThisBeforeShippingToProdOrYouWillBeFired",
password: "ChangeThisBeforeShippingToProdOrYouWillBeFired",
const API_KEY = "lv2_prod_f10d28b9ef5694e38b61eb614556ed85ab480585ef03c39c";
token: "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
token: "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
debug.keystore
gradle-wrapper.jar
.lintstagedrc
.example.env
.prettierignore
.prettierrc.json
.env.local.example
console.log(`Failed to load image for ${token.symbol}`);console.log(`Failed to load image for ${token.symbol}`);import OkxPlugin from '../../../packages/plugin-defi/src/okx';
import { cn } from '../../lib/utils';import { cn } from '../../lib/utils';const uploadsDir = path.join(__dirname, '../../uploads');
import COLORS from '../../assets/colors';
@langchain/core, @langchain/langgraph, @langchain/langgraph-checkpoint-postgres, @langchain/openai, @solana-agent-kit/plugin-defi, @solana-agent-kit/plugin-token, @solana/web3.js, bs58
Gates applied: no_behavioural_pass.
6fef39b5e832full audit observations/trust-audit/mcp-server/sendaifun__solana-agent-kit-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 6fef39b5e832 | CAUTION | F | 60 | source changed, verdict held |
Questions
What is the Solana Agent Kit MCP server?
connect any ai agents to solana protocols
What tools does Solana Agent Kit expose?
69 in total: 61 read-only, 8 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Solana Agent Kit safe to connect to an agent?
With care. The audit graded it F (60/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Solana Agent Kit need?
It reads ANTHROPIC_API_KEY, DISCORD_BOT_TOKEN, FLEXLEND_API_KEY, HELIUS_API_KEY, NEXT_PUBLIC_AUTH_IFRAME_URL, NEXT_PUBLIC_FIREBASE_API_KEY, NEXT_PUBLIC_FIREBASE_AUTH_DOMAIN, NEXT_PUBLIC_OPENAI_API_KEY, NEXT_PUBLIC_TURNKEY_API_PRIVATE_KEY, NEXT_PUBLIC_TURNKEY_API_PUBLIC_KEY, OKX_API_KEY and OKX_API_PASSPHRASE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Solana Agent Kit run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as integration-test at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (6fef39b5e832), read on 2026-09-23. The repository is watched and re-audited when it changes.