Atlas / MCP servers / sendaifun / Solana Agent Kit

Solana Agent KitCAUTION

mcp/sendaifun/solana-agent-kit-2

connect any ai agents to solana protocols

Verdict
CAUTION
Grade
F
Trust score
60 /100
Exposed tools
69 61r · 8w · 0d
Transport
stdio
License
Apache-2.0
Stars
1,713
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[!TIP] checkout Suzi 🌸 by SendAI

[](https://www.npmjs.com/package/solana-agent-kit) [](https://github.com/sendaifun/solana-agent-kit/network/members) [](https://github.com/sendaifun/solana-agent-kit/blob/v2/LICENSE)

An open-source toolkit for connecting AI agents to Solana protocols. Now, any agent, using any model can autonomously perform 60+ Solana actions:

  • Trade tokens
  • Launch new tokens
  • Lend assets
  • Send compressed airdrops
  • Execute blinks
  • Launch tokens on AMMs
  • Bridge tokens across chains
  • And more...

Anyone - whether an SF-based AI researcher or a crypto-native builder - can bring their AI agents trained with any model and seamlessly integrate with Solana.

[](https://replit.com/@sendaifun/Solana-Agent-Kit)

Replit template created by Arpit Singh

🔧 Core Blockchain Features

  • Token Operations
  • Deploy SPL tokens by Metaplex
  • Transfer assets
  • Balance checks
  • Stake SOL
  • Zk compressed Airdrop by Light Protocol and Helius
  • Bridge tokens across chains using Wormhole
  • NFTs on 3.Land
  • Create your own collection
  • NFT creation and automatic listing on 3.land
  • List your NFT for sale in any SPL token
  • NFT Management via Metaplex
  • Collection deployment
  • NFT minting
  • Metadata management
  • Royalty configuration
  • DeFi Integration
  • Jupiter Exchange swaps
  • Launch on Pump via PumpPortal
  • Raydium pool creation (CPMM, CLMM, AMMv4)
  • Orca
Read from source at commit 6fef39b5e832OBSERVED · 2026-09-23
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add integration-test --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env DISCORD_BOT_TOKEN=${DISCORD_BOT_TOKEN} --env FLEXLEND_API_KEY=${FLEXLEND_API_KEY} --env HELIUS_API_KEY=${HELIUS_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "integration-test": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "DISCORD_BOT_TOKEN": "${DISCORD_BOT_TOKEN}",
        "FLEXLEND_API_KEY": "${FLEXLEND_API_KEY}",
        "HELIUS_API_KEY": "${HELIUS_API_KEY}"
      }
    }
  }
}
03

Exposed tools (69)

61 read · 8 write · 0 destructive.

ToolRiskDescription
AVAILABLE_DRIFT_MARKETSreadGet a list of available drift markets
BID_ON_MAGICEDEN_NFTreadPlace a bid on an NFT listed on MagicEden
CLAIM_PARA_PREGEN_WALLETreadClaim a pregen wallet for Para
CREATE_METEORA_DLMM_POOLwriteCreate a new Meteora DLMM pool
CREATE_METEORA_DYNAMIC_AMM_POOLwriteCreate a new dynamic AMM pool on Meteora
CREATE_ORCA_CLMM_ACTIONwriteCreate a Concentrated Liquidity Market Maker (CLMM) pool on Orca, the most efficient and capital-optimized CLMM on Solana. This function initializes a CLMM pool but does not add liquidity. You can add liquidity later using a centered position or a single-sided position.
DEBRIDGE_CREATE_BRIDGE_ORDERwriteCreate a cross-chain bridge order using deBridge to transfer tokens between chains. Returns both the transaction data and estimated amounts.
DEBRIDGE_EXECUTE_BRIDGE_ORDERwriteExecute a cross-chain bridge transaction on Solana using deBridge with the transaction data from DEBRIDGE_CREATE_BRIDGE_ORDER.
DEBRIDGE_GET_SUPPORTED_CHAINSreadFetch the list of chains supported by deBridge for cross-chain token transfers
DEBRIDGE_GET_TOKENS_INFOreadGet information about tokens available for cross-chain bridging via deBridge protocol. First use DEBRIDGE_GET_SUPPORTED_CHAINS to get the list of valid chain IDs, then provide the chain ID from that list. For EVM chains: use 0x-prefixed address. For Solana: use base58 token address.
DEPOSIT_INTO_DRIFT_VAULTreadDeposit funds into an existing drift vault
DEPOSIT_TO_DRIFT_USER_ACCOUNTreadDeposit funds into your drift user account
DOES_USER_HAVE_DRIFT_ACCOUNTreadCheck if a user has a Drift account
DRIFT_GET_ENTRY_QUOTE_OF_PERP_TRADE_ACTIONreadGet the entry quote of a perpetual trade on Drift
DRIFT_GET_LEND_AND_BORROW_APY_ACTIONreadGet the lending and borrowing APY (in %) of a token on Drift
DRIFT_PERP_MARKET_FUNDING_RATE_ACTIONreadGet the funding rate of a perpetual market on Drift
DRIFT_SPOT_TOKEN_SWAP_ACTIONreadSwap a token for another token on Drift
FETCH_ORCA_POSITIONS_ACTIONreadFetch all the liquidity positions in an Orca Whirlpool by owner. Returns an object with position mint addresses as keys and position status details as values.
GET_ALL_WALLETSreadGet all wallets
GET_COINGECKO_LATEST_POOLSreadGet the latest pools on Coingecko
GET_COINGECKO_TOKEN_INFO_ACTIONreadGet token information from Coingecko
GET_COINGECKO_TOKEN_PRICE_DATA_ACTIONreadGet the price data of a token on Coingecko
GET_COINGECKO_TOP_GAINERSreadGet the top gainers on Coingecko
GET_COINGECKO_TRENDING_POOLS_ACTIONreadGet the trending pools on Coingecko
GET_COINGECKO_TRENDING_TOKENS_ACTIONreadGet the trending tokens on Coingecko
GET_MAGICEDEN_COLLECTION_LISTINGSreadFetch listings for a specific NFT collection on MagicEden
GET_MAGICEDEN_COLLECTION_STATSreadFetch statistics for a specific NFT collection on MagicEden
GET_POPULAR_MAGICEDEN_COLLECTIONSreadFetch popular NFT collections from MagicEden
HOMOMEMETUS_FETCH_OLDEST_TOKENreadOldest token list from token list created in 24h
HOMOMEMETUS_FETCH_RECENT_TOKENreadRecent token list from token list created in 24h
HOMOMEMETUS_FETCH_TOKENS_BY_CREATORSreadCreator-address-list-based token filter
HOMOMEMETUS_FETCH_TOKENS_BY_DURATIONreadCreation-time-based token filter
HOMOMEMETUS_FETCH_TOKENS_BY_INITIALIZERreadInitializer-address-list-based token filter
HOMOMEMETUS_FETCH_TOKENS_BY_MARKET_CAPreadMarket-cap-based token filter
HOMOMEMETUS_FETCH_TOKENS_BY_METADATAreadMetadata-based token filter
HOMOMEMETUS_FETCH_TOKENS_BY_MINTSreadMint-addresses-based token filter
HOMOMEMETUS_FETCH_TOKEN_BY_CREATORreadCreator-address-based token filter
HOMOMEMETUS_FETCH_TOKEN_BY_INITIALIZERreadInitializer-address-based token filter
HOMOMEMETUS_FETCH_TOKEN_BY_MINTreadMint-address-based token filter
HOMOMEMETUS_FETCH_TOKEN_BY_SIGNATUREreadCreation-signature-based token filter
LIST_MAGICEDEN_NFTreadList an NFT for sale on MagicEden
OKX_EXECUTE_SWAPwriteExecute swap through okx dex
OKX_GET_CHAIN_DATAreadGet Chain data from okx dex
OKX_GET_LIQUIDITYreadGet liquidity data from okx dex
OKX_GET_QUOTEreadGet quote data from okx dex
OKX_GET_SWAP_DATAreadGet swap instruction data from okx dex
OKX_GET_TOKENreadGet token data from okx dex
OPEN_ORCA_CENTERED_POSITION_WITH_LIQUIDITY_ACTIONreadOpen a new Orca whirlpool position with liquidity centered around the current price. This function opens a new liquidity position in an Orca whirlpool with the provided liquidity amount centered around the current price.
OPEN_ORCA_SINGLE_SIDED_POSITION_ACTIONreadOpen a single-sided liquidity position in an Orca Whirlpool
OSEC_CREATE_VERIFICATION_PDAwriteGenerate a PDA for program verification and verify the program using Otter Sec
OSEC_DECODE_VERIFICATION_PDA_DATAreadDecode the PDA data composed in hex.
OSEC_GET_PROGRAM_BUILD_LOGreadGet program build for a solana program
OSEC_GET_PROGRAM_VERIFICATION_STATUSreadGet program verification status
OSEC_GET_VERIFICATION_JOB_STATUSreadGet status of an async verification job
OSEC_GET_VERIFIED_PROGRAMreadGet list of all verified programs
OSEC_VERIFY_PROGRAMreadVerify a Solana program
REQUEST_UNSTAKE_FROM_DRIFT_INSURANCE_FUND_ACTIONreadRequest to unstake a certain amount of a token from the Drift Insurance Fund
REQUEST_WITHDRAWAL_FROM_DRIFT_VAULTreadRequest a withdrawal from an existing drift vault
RUGCHECKreadCheck if a token is a rug pull
SOLUTIOFI_BURN_TOKENSreadBurn tokens using SolutioFi
SOLUTIOFI_CLOSE_ACCOUNTSreadClose specific token accounts using SolutioFi
SOLUTIOFI_MERGE_TOKENSwriteMerge multiple tokens into one using SolutioFi
SOLUTIOFI_SPREAD_TOKENreadSplit a token into multiple tokens using SolutioFi
STAKE_TO_DRIFT_INSURANCE_FUND_ACTIONreadStake a token to Drift Insurance Fund
UNSTAKE_FROM_DRIFT_INSURANCE_FUND_ACTIONreadUnstake requested unstake token from the Drift Insurance fund once the cool period has elapsed
USE_WALLETreadUse a wallet
WITHDRAW_FROM_DRIFT_VAULTreadWithdraw funds from a vault given the redemption time has elapsed.
WITHDRAW_OR_BORROW_FROM_DRIFT_ACCOUNTreadWithdraw funds from your drift account
search_state_of_unionreadSearches and returns documents regarding the state-of-the-union.
04

Trust audit

CAUTIONgrade F · trust 60/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
packages/plugin-defi/src/debridge/actions/executeBridgeOrder.ts:22
"0x23b872dd000000000000000000000000742d35cc6634c0532925a3b844bc454e4438f44e000000000000000000000000e7351fd770a37282b91d153ee690b63579b6e837000000000000000000000000000000000000000000000000000de0b6b3a76
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
packages/plugin-defi/src/okx/actions/getSwapData.ts:94
data: "3UfFcAn6toX6QG3XuYGFA24PKaK4o62QKQQTD4fBR1U7nKPurhPBnLWXZsAymchhkAM9kHJKM3moahBMR9sJUmGHdL59gxq6PXidgJ5e7FUuePqzCRyutowo5qXSGARUpuJ46eMcXG2SgFo3pHx1bi3WHnJMydkj3UfEJcmRQrKyzYQGeAP9njjB1QbRcUudt
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
packages/plugin-misc/src/elfaai/actions/index.ts:379
"FGluY2x1ZGVfY29udGV4dF91dWlkDnF1ZXJ5VGhlbkZldGNoAxZBNTBtYmVEM1RUR2NycUdHUE9GMnN3AAAAAABm5oUWVERUVURyRHFRZ2VYY1F0cVh1UWloZxZMdjdsV2N5TVMzLU9LZkNFOWVWVlBBAAAAAAA25W0WWXBqUmN2eXlUNUdjakhFOGZ5XzZ5ZxZaZGp
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
packages/plugin-misc/src/ottersec/actions/decodeVerificationPdaData.ts:18
hex: "ce65c2888771730ca28e257dae8c81dc8ce27c9cc2451fb1837c52039847481f5b65cc6f152573c3efae07731701872e5391cb1a51627c845f1e12e9754d110f87751ac868003b5f05000000302e342e383300000068747470733a2f2f67697468
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
packages/plugin-misc/src/solanafm/actions/parseInstruction.ts:22
"3UwpeiMtquiTRwEh3LDXQ2ackEUawDAPVnEmbcfFU66N4Knmo4ArVS1XPSjj5UvUtsdQSxGcksSP5ERNDR36DFz8VnkSNBBFt5LfGc3WV7nDpqSfrcguxcMSgE7it74MGBBXUix9tPdKxxete8o4DKEUyt4b6mWnR9DbnyiNL8JnhAddSh99YP8zXGAFboUYejp5sVo
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
examples/embedded-wallets/crossmint-sak-v2/src/utils/session.ts:6
password: "ChangeThisBeforeShippingToProdOrYouWillBeFired",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
examples/embedded-wallets/privy-agent-tanstack-starter/src/utils/session.ts:6
password: "ChangeThisBeforeShippingToProdOrYouWillBeFired",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/plugin-defi/src/lavarage/tools/lavarage.ts:6
const API_KEY = "lv2_prod_f10d28b9ef5694e38b61eb614556ed85ab480585ef03c39c";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/plugin-token/src/solana/actions/balance.ts:38
token: "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/plugin-token/src/solana/actions/transfer.ts:47
token: "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
LOWInventory / provenance · inv.binary · CWE-1104
examples/embedded-wallets/privy-sak-react-native/android/app/debug.keystore
debug.keystore
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
examples/embedded-wallets/privy-sak-react-native/android/gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.lintstagedrc
.lintstagedrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
examples/defi/wormhole-nextjs-agent/.example.env
.example.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
examples/embedded-wallets/crossmint-sak-v2/.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
examples/embedded-wallets/para-plugin-example/.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
examples/embedded-wallets/phantom-agent-starter/.env.local.example
.env.local.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
examples/embedded-wallets/crossmint-sak-v2/src/components/TokenCard.tsx:22
console.log(`Failed to load image for ${token.symbol}`);
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
examples/embedded-wallets/privy-agent-tanstack-starter/src/components/TokenCard.tsx:22
console.log(`Failed to load image for ${token.symbol}`);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/defi/okx-dex-starter/index.ts:5
import OkxPlugin from '../../../packages/plugin-defi/src/okx';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/embedded-wallets/crossmint-sak-v2/src/components/ui/icon.tsx:2
import { cn } from '../../lib/utils';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/embedded-wallets/privy-agent-tanstack-starter/src/components/ui/icon.tsx:2
import { cn } from '../../lib/utils';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/embedded-wallets/privy-sak-react-native/server/controllers/fileController.ts:8
const uploadsDir = path.join(__dirname, '../../uploads');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/embedded-wallets/privy-sak-react-native/src/screens/LoginScreen/LoginScreen.styles.ts:2
import COLORS from '../../assets/colors';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/defi/market-making-agent/package.json
@langchain/core, @langchain/langgraph, @langchain/langgraph-checkpoint-postgres, @langchain/openai, @solana-agent-kit/plugin-defi, @solana-agent-kit/plugin-token, @solana/web3.js, bs58
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-09-23 · audit v0.4.1 · source sha 6fef39b5e832full audit observations/trust-audit/mcp-server/sendaifun__solana-agent-kit-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-236fef39b5e832CAUTIONF60source changed, verdict held
06

Questions

What is the Solana Agent Kit MCP server?

connect any ai agents to solana protocols

What tools does Solana Agent Kit expose?

69 in total: 61 read-only, 8 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Solana Agent Kit safe to connect to an agent?

With care. The audit graded it F (60/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Solana Agent Kit need?

It reads ANTHROPIC_API_KEY, DISCORD_BOT_TOKEN, FLEXLEND_API_KEY, HELIUS_API_KEY, NEXT_PUBLIC_AUTH_IFRAME_URL, NEXT_PUBLIC_FIREBASE_API_KEY, NEXT_PUBLIC_FIREBASE_AUTH_DOMAIN, NEXT_PUBLIC_OPENAI_API_KEY, NEXT_PUBLIC_TURNKEY_API_PRIVATE_KEY, NEXT_PUBLIC_TURNKEY_API_PUBLIC_KEY, OKX_API_KEY and OKX_API_PASSPHRASE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Solana Agent Kit run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as integration-test at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (6fef39b5e832), read on 2026-09-23. The repository is watched and re-audited when it changes.

Advertisement