From dd529319c9f6c2df4ce5b429312fbfd5a05f035b Mon Sep 17 00:00:00 2001 From: Raffx Date: Mon, 22 Jun 2026 15:06:40 -0300 Subject: [PATCH 01/16] =?UTF-8?q?Add=20sign-safe=20=E2=80=94=20offline=20s?= =?UTF-8?q?igning-time=20transaction=20safety=20gate?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Opus 4.8 (1M context) --- .gitmodules | 3 +++ sign-safe-skill | 1 + 2 files changed, 4 insertions(+) create mode 100644 .gitmodules create mode 160000 sign-safe-skill diff --git a/.gitmodules b/.gitmodules new file mode 100644 index 0000000..f9f2de9 --- /dev/null +++ b/.gitmodules @@ -0,0 +1,3 @@ +[submodule "sign-safe-skill"] + path = sign-safe-skill + url = https://github.com/lrafasouza/sign-safe-skill diff --git a/sign-safe-skill b/sign-safe-skill new file mode 160000 index 0000000..94402e2 --- /dev/null +++ b/sign-safe-skill @@ -0,0 +1 @@ +Subproject commit 94402e2689dd5b392cbddd2bc833a4c7b33413b0 From 94aaadf835a9bb1cc2a3ccb1bf1a039fb5a54677 Mon Sep 17 00:00:00 2001 From: Raffx Date: Mon, 22 Jun 2026 16:52:27 -0300 Subject: [PATCH 02/16] =?UTF-8?q?chore:=20bump=20sign-safe=20submodule=20?= =?UTF-8?q?=E2=80=94=20Solana=20clear-signing=20(Squads=20inner=20decode),?= =?UTF-8?q?=20238=20tests?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Opus 4.8 (1M context) --- sign-safe-skill | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sign-safe-skill b/sign-safe-skill index 94402e2..edbc45b 160000 --- a/sign-safe-skill +++ b/sign-safe-skill @@ -1 +1 @@ -Subproject commit 94402e2689dd5b392cbddd2bc833a4c7b33413b0 +Subproject commit edbc45bcdf18473faa86dc5c372aa995b9134aa0 From 274188dbeb2cbfd61b490826249f7b7495f3138b Mon Sep 17 00:00:00 2001 From: Raffx Date: Mon, 22 Jun 2026 22:17:27 -0300 Subject: [PATCH 03/16] =?UTF-8?q?chore:=20bump=20sign-safe=20submodule=20?= =?UTF-8?q?=E2=80=94=20drainer=20coverage,=20292=20tests?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Opus 4.8 (1M context) --- sign-safe-skill | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sign-safe-skill b/sign-safe-skill index edbc45b..3637dd4 160000 --- a/sign-safe-skill +++ b/sign-safe-skill @@ -1 +1 @@ -Subproject commit edbc45bcdf18473faa86dc5c372aa995b9134aa0 +Subproject commit 3637dd4b2920c053333ef164a1038e5f6801986f From 4e9914aca418b8f0c48eac08c7f8f0884dc708ca Mon Sep 17 00:00:00 2001 From: Raffx Date: Tue, 23 Jun 2026 09:57:17 -0300 Subject: [PATCH 04/16] chore: bump sign-safe-skill submodule to v0.4.0 (99165f3) sign-safe v0.4: ALT resolution + Token-2022 mint screening + Squads clear-sign via --rpc, two-tier REJECT posture + --strict, 12-program registry, real-mainnet precision study. 607 tests. Co-Authored-By: Claude Opus 4.8 (1M context) --- sign-safe-skill | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sign-safe-skill b/sign-safe-skill index 3637dd4..99165f3 160000 --- a/sign-safe-skill +++ b/sign-safe-skill @@ -1 +1 @@ -Subproject commit 3637dd4b2920c053333ef164a1038e5f6801986f +Subproject commit 99165f3bb8b566f649e056898ca5235448c9b64d From 6589c69d673284db4b32b465f24434adb4d4b0bf Mon Sep 17 00:00:00 2001 From: Raffx Date: Tue, 23 Jun 2026 10:06:24 -0300 Subject: [PATCH 05/16] chore: bump sign-safe-skill submodule to 9baabb3 (v0.4 + CI actions v5) Co-Authored-By: Claude Opus 4.8 (1M context) --- sign-safe-skill | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sign-safe-skill b/sign-safe-skill index 99165f3..9baabb3 160000 --- a/sign-safe-skill +++ b/sign-safe-skill @@ -1 +1 @@ -Subproject commit 99165f3bb8b566f649e056898ca5235448c9b64d +Subproject commit 9baabb32e705cf66989327e0d867ca01fbf8de14 From 06816634140ed78abed499f00dbae4ee76f71a0d Mon Sep 17 00:00:00 2001 From: Raffx Date: Thu, 25 Jun 2026 11:34:22 -0300 Subject: [PATCH 06/16] chore: bump sign-safe-skill to v0.5.0 (4cc33c1) v0.5: simulation, Native Stake, programmatic API + signTransaction/MWA gate + MCP server, schema (requiresHumanReview/category), durable-nonce asymmetry, Lighthouse INFO, Marginfi/Squads registry; full adversarial review + 3 fix passes; 728 tests. --- sign-safe-skill | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sign-safe-skill b/sign-safe-skill index 9baabb3..4cc33c1 160000 --- a/sign-safe-skill +++ b/sign-safe-skill @@ -1 +1 @@ -Subproject commit 9baabb32e705cf66989327e0d867ca01fbf8de14 +Subproject commit 4cc33c1250730c6f336b8e75cca833f55a00d2c5 From 656ea1f77eba6cdc8230dbb867eb93b34608c024 Mon Sep 17 00:00:00 2001 From: Rafael Date: Sat, 27 Jun 2026 00:32:46 -0300 Subject: [PATCH 07/16] chore: update sign-safe proof packet --- sign-safe-skill | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sign-safe-skill b/sign-safe-skill index 4cc33c1..7a785d6 160000 --- a/sign-safe-skill +++ b/sign-safe-skill @@ -1 +1 @@ -Subproject commit 4cc33c1250730c6f336b8e75cca833f55a00d2c5 +Subproject commit 7a785d68bcf6cc07e38cd0a5f96320e8b304609d From 7cc4966b61ed979858b207cfaec50aed85b7d975 Mon Sep 17 00:00:00 2001 From: Rafael Date: Sat, 27 Jun 2026 14:34:50 -0300 Subject: [PATCH 08/16] chore: bump sign-safe skill proof packet --- sign-safe-skill | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sign-safe-skill b/sign-safe-skill index 7a785d6..9621c54 160000 --- a/sign-safe-skill +++ b/sign-safe-skill @@ -1 +1 @@ -Subproject commit 7a785d68bcf6cc07e38cd0a5f96320e8b304609d +Subproject commit 9621c546b1cfd0495388b03da8e69635c381d233 From cee31081f715d07b2c6b9af45da4f3a96602a85b Mon Sep 17 00:00:00 2001 From: Rafael Date: Sat, 27 Jun 2026 14:46:19 -0300 Subject: [PATCH 09/16] chore: bump sign-safe skill draft ignore --- sign-safe-skill | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sign-safe-skill b/sign-safe-skill index 9621c54..3cfb582 160000 --- a/sign-safe-skill +++ b/sign-safe-skill @@ -1 +1 @@ -Subproject commit 9621c546b1cfd0495388b03da8e69635c381d233 +Subproject commit 3cfb582294f51ab6c1f0419c43ea9c4990e56b46 From 3f290788ed3dae2bd42960a928969fdce511e625 Mon Sep 17 00:00:00 2001 From: Rafael Date: Mon, 29 Jun 2026 10:40:41 -0300 Subject: [PATCH 10/16] chore: bump sign-safe submodule to v0.5.1 (main 910b089) Reflects the competitive-analysis release: evaluator Quickstart, reproducible sample verdicts, Squads HOLD walkthrough, MCP example, failure-recovery doc, CLI e2e + RPC-adversarial tests; 777 tests / 40 files, verify:all green. Co-Authored-By: Claude Opus 4.8 (1M context) --- sign-safe-skill | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sign-safe-skill b/sign-safe-skill index 3cfb582..910b089 160000 --- a/sign-safe-skill +++ b/sign-safe-skill @@ -1 +1 @@ -Subproject commit 3cfb582294f51ab6c1f0419c43ea9c4990e56b46 +Subproject commit 910b089cf9492814241e9e3766b674d53e604321 From 730425346320093a998a90776824afd91b0786c1 Mon Sep 17 00:00:00 2001 From: Rafael Date: Mon, 29 Jun 2026 19:07:59 -0300 Subject: [PATCH 11/16] chore: bump sign-safe submodule to v0.6.0 (main c32c8da) Real on-chain Drift attack corpus (held), npm sign-safe, rpc-adversarial coverage, fuzz + fail-closed fix. 800 tests/42 files, verify:all green. Co-Authored-By: Claude Opus 4.8 (1M context) --- sign-safe-skill | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sign-safe-skill b/sign-safe-skill index 910b089..c32c8da 160000 --- a/sign-safe-skill +++ b/sign-safe-skill @@ -1 +1 @@ -Subproject commit 910b089cf9492814241e9e3766b674d53e604321 +Subproject commit c32c8da66a14d18eeac197bab74c0a11eb546b4d From 96113f71f410eb2dc1ba3cd8d36bdb69b284cf65 Mon Sep 17 00:00:00 2001 From: Rafael Date: Mon, 29 Jun 2026 20:01:49 -0300 Subject: [PATCH 12/16] chore: bump sign-safe submodule to v0.6.1 (main 3fada15) IDL-verified registry (69/69 ixNames vs canonical IDLs), benign corpus 500 (18.4% SIGN / 81.6% HOLD / 0 false-REJECT), Stryker mutation testing. verify:all green. Co-Authored-By: Claude Opus 4.8 (1M context) --- sign-safe-skill | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sign-safe-skill b/sign-safe-skill index c32c8da..3fada15 160000 --- a/sign-safe-skill +++ b/sign-safe-skill @@ -1 +1 @@ -Subproject commit c32c8da66a14d18eeac197bab74c0a11eb546b4d +Subproject commit 3fada154a0d1070529dc1aebe1b9b7fd3cdc5e70 From 295fbd3f5756c7b5432402e846c4edfa0337f503 Mon Sep 17 00:00:00 2001 From: Rafael Date: Mon, 29 Jun 2026 20:21:54 -0300 Subject: [PATCH 13/16] chore: bump sign-safe submodule to v0.6.2 (main 02b3150) Fix: npx sign-safe bin was inert (exit 0 for every tx); now correct exit codes + regression test. 803 tests/42 files, verify:all green. Co-Authored-By: Claude Opus 4.8 (1M context) --- sign-safe-skill | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sign-safe-skill b/sign-safe-skill index 3fada15..02b3150 160000 --- a/sign-safe-skill +++ b/sign-safe-skill @@ -1 +1 @@ -Subproject commit 3fada154a0d1070529dc1aebe1b9b7fd3cdc5e70 +Subproject commit 02b3150cec9e48fcbf5b287e9ceb473d6520a714 From a3a1b95d138e042059b6684424cdc4aa57326732 Mon Sep 17 00:00:00 2001 From: Rafael Date: Tue, 30 Jun 2026 11:55:25 -0300 Subject: [PATCH 14/16] chore: bump sign-safe submodule to v0.6.4 + security (main e288e9d) Updates the pinned sign-safe-skill from v0.6.2 (02b3150) to the current main (e288e9d): v0.6.4 (npm-published, README install + What's-new) plus the repo security hardening (CI least-privilege + SHA-pinned actions, Dependabot, branch protection). Co-Authored-By: Claude Opus 4.8 (1M context) --- sign-safe-skill | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sign-safe-skill b/sign-safe-skill index 02b3150..e288e9d 160000 --- a/sign-safe-skill +++ b/sign-safe-skill @@ -1 +1 @@ -Subproject commit 02b3150cec9e48fcbf5b287e9ceb473d6520a714 +Subproject commit e288e9dc9760501399b02e905e1007fa210b9ddf From 841f47fdb4a63c3d652e987a560cca7341d82c11 Mon Sep 17 00:00:00 2001 From: Rafael Date: Tue, 30 Jun 2026 12:11:25 -0300 Subject: [PATCH 15/16] docs: add submission landing README (self-describing for reviewers) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The submission is a submodule pin, so the PR tree showed only an opaque gitlink. Add a concise README presenting sign-safe — the verdict model, npx install, real-Drift-attack evidence, test/precision numbers, honest scope, and links — so a reviewer can evaluate it without clicking through the submodule. Mirrors the strongest file-based submissions. Co-Authored-By: Claude Opus 4.8 (1M context) --- README.md | 41 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 41 insertions(+) create mode 100644 README.md diff --git a/README.md b/README.md new file mode 100644 index 0000000..4081d93 --- /dev/null +++ b/README.md @@ -0,0 +1,41 @@ +# sign-safe — offline signing-time safety gate for Solana + +> Submission for the **Solana AI Kit** skill bounty. The skill lives in the [`sign-safe-skill`](./sign-safe-skill) submodule (`lrafasouza/sign-safe-skill`) and is published to npm as [`sign-safe`](https://www.npmjs.com/package/sign-safe). Kit integration: [solana-ai-kit#34](https://github.com/solanabr/solana-ai-kit/pull/34). + +**What does this Solana transaction do to *me* — before I sign it?** Wallets show a blob. Auditors read code you already wrote. Debuggers explain failures after they land. None answer the question that matters at signing time. sign-safe does. + +Hand it opaque base64 transaction bytes. It decodes them **offline** — legacy + v0 + Address Lookup Tables, durable nonces, Token-2022, Squads v4 proposals — classifies danger primitives, computes signer-perspective outflow, and emits a verdict with the CLI exit code mirroring it: + +| Verdict | Exit | Meaning | +|---|---|---| +| **SIGN** | `0` | Recognized benign shapes under policy. *Not* a guarantee of intent. | +| **HOLD** | `10` | Needs a human / higher-trust policy before signing. | +| **REJECT** | `20` | Known dangerous shape, or bytes that can't be trusted. | + +## Try it (no clone) + +```bash +npx sign-safe # 0 SIGN · 10 HOLD · 20 REJECT +cat tx.b64 | npx sign-safe # or pipe base64 on stdin +npx sign-safe-mcp # zero-dependency MCP server for agents +``` + +No key, no RPC, no broadcast — the deterministic core is offline by design. + +## Why it's different + +- **Real on-chain attack evidence.** The actual transactions that drained Drift (~$285M, Apr 2026) decode to **HOLD** *before* signing — durable-nonce advance + Squads v4 execution. That's the exact authority-handoff shape simulation/balance-diff checks miss, because nothing needs to move at signing time for the transaction to be dangerous. +- **Honest by construction.** SIGN is the *weakest* claim in the system ("nothing here is recognized as dangerous"), never "this is safe." Malformed, unknown, or unresolved structure fails closed into HOLD/REJECT — never silent approval. +- **Tested, reported as-is.** 803 tests / 42 files · 14-program clear-signing registry with **69/69** Anchor discriminators cross-verified against canonical on-chain IDLs · mutation testing (Stryker, 70.2% behavioral) + fuzz (44,288 single-byte mutations of an authority transfer → **0** ever flip to SIGN) · 500 benign mainnet txs → 18.4% SIGN / 81.6% HOLD / **0 false-REJECT**. Zero runtime dependencies. MIT. + +## Scope (honest limits) + +Pre-sign review, **not** on-chain enforcement. The 37/37 attack-replay and 100%-recall figures are over a curated, mostly-synthetic corpus — not a population sample. sign-safe complements simulation, wallet UX, human review, and multisig/policy systems. + +## Links + +- 📦 npm: https://www.npmjs.com/package/sign-safe +- 📂 Repo (full docs, danger catalog, 3-minute evaluator quickstart): https://github.com/lrafasouza/sign-safe-skill +- 🔗 Kit integration PR: https://github.com/solanabr/solana-ai-kit/pull/34 + +Full documentation is in the [`sign-safe-skill`](./sign-safe-skill) submodule's `README.md` and `SKILL.md`. From 3532eb49b8c9fbbdffc7bb17baaed0beb530a68a Mon Sep 17 00:00:00 2001 From: Rafael Date: Tue, 30 Jun 2026 12:27:32 -0300 Subject: [PATCH 16/16] docs: expand submission README to match the bar (catch-list, real CLI output, agent usage) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Enriched the landing README after reviewing peer submissions (#5 strongest, #28 closest competitor): added npm/CI/license badges, a concrete "what it catches" primitive list, verbatim SIGN/REJECT CLI output, Claude/agent + MCP + guardedSignTransaction usage, the proof numbers, and honest scope — so a judge can fully evaluate the skill from the PR without clicking through the submodule. Co-Authored-By: Claude Opus 4.8 (1M context) --- README.md | 69 +++++++++++++++++++++++++++++++++++++++++++++++-------- 1 file changed, 60 insertions(+), 9 deletions(-) diff --git a/README.md b/README.md index 4081d93..e655292 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,10 @@ # sign-safe — offline signing-time safety gate for Solana -> Submission for the **Solana AI Kit** skill bounty. The skill lives in the [`sign-safe-skill`](./sign-safe-skill) submodule (`lrafasouza/sign-safe-skill`) and is published to npm as [`sign-safe`](https://www.npmjs.com/package/sign-safe). Kit integration: [solana-ai-kit#34](https://github.com/solanabr/solana-ai-kit/pull/34). +[![npm version](https://img.shields.io/npm/v/sign-safe.svg)](https://www.npmjs.com/package/sign-safe) +[![CI](https://github.com/lrafasouza/sign-safe-skill/actions/workflows/ci.yml/badge.svg)](https://github.com/lrafasouza/sign-safe-skill/actions/workflows/ci.yml) +[![license: MIT](https://img.shields.io/npm/l/sign-safe.svg)](https://github.com/lrafasouza/sign-safe-skill/blob/main/LICENSE) + +> Submission for the **Solana AI Kit** skill bounty. Not a link-only placeholder: a runnable, tested, **npm-published** skill. The full source lives in the [`sign-safe-skill`](./sign-safe-skill) submodule (`lrafasouza/sign-safe-skill`); install it directly as [`sign-safe`](https://www.npmjs.com/package/sign-safe). Kit integration: [solana-ai-kit#34](https://github.com/solanabr/solana-ai-kit/pull/34). **What does this Solana transaction do to *me* — before I sign it?** Wallets show a blob. Auditors read code you already wrote. Debuggers explain failures after they land. None answer the question that matters at signing time. sign-safe does. @@ -17,25 +21,72 @@ Hand it opaque base64 transaction bytes. It decodes them **offline** — legacy ```bash npx sign-safe # 0 SIGN · 10 HOLD · 20 REJECT cat tx.b64 | npx sign-safe # or pipe base64 on stdin -npx sign-safe-mcp # zero-dependency MCP server for agents +npx sign-safe --json # verdict.json only, for agents + +npx sign-safe-mcp # zero-dependency MCP server (tool: review_transaction) +``` + +For Claude / agents: the skill exposes a `/sign-review` command and an MCP `review_transaction` tool with a published `outputSchema`, plus a `guardedSignTransaction` wrapper that throws on REJECT *before* the key is touched. No key, no RPC, no broadcast — the deterministic core is offline by design. + +## Real output + +```text +$ npx sign-safe safe-transfer.b64 +[ SIGN ] Recognized instructions within thresholds; no danger primitives, unknown + programs, or unverified ALT references. sends 10000000 lamports to 9hSR6S7W… + Not a guarantee of intent — verify the recipients and amounts yourself. +worst severity: INFO · static outflow: 10000000 lamports · findings: 0 (exit 0) + +$ npx sign-safe setauthority.b64 +[ REJECT ] Contains a REJECT-class danger primitive: SPL Token SetAuthority. +findings (1): + - [REJECT] ix#0 SPL Token SetAuthority + maps to loss: Hands mint/freeze/owner authority to an attacker, who can then + mint, freeze, or seize at will. (exit 20) ``` -No key, no RPC, no broadcast — the deterministic core is offline by design. +## What it catches (the shapes simulation/balance-diff checks miss) + +A danger move at signing time often moves **zero** tokens — so wallet simulation shows nothing. sign-safe reads the *intent* in the bytes: + +- **Owner reassignment** — System `Assign` +- **Token authority handoff** — SPL `SetAuthority` (mint / freeze / account owner) +- **Unlimited delegate** — SPL `Approve` +- **Account close / rent drain**, and NFT-theft shapes +- **Durable-nonce replay** — the documented 2026 Drift (~$285M) vector +- **Program upgrade-authority swap** — BPF loader TOCTOU +- **Token-2022 traps** — permanent-delegate, transfer-hook +- **Squads v4 proposals** — decodes the *hidden inner instruction* and names it +- **ALT-obscured accounts / unknown programs / unresolved references** → fail-closed (never silent SIGN) + +A 14-program clear-signing registry (Jupiter, Orca, Raydium, Kamino, Drift, …) recognizes benign DeFi/NFT instructions so they don't drown the real signals; everything unrecognized stays conservative. ## Why it's different -- **Real on-chain attack evidence.** The actual transactions that drained Drift (~$285M, Apr 2026) decode to **HOLD** *before* signing — durable-nonce advance + Squads v4 execution. That's the exact authority-handoff shape simulation/balance-diff checks miss, because nothing needs to move at signing time for the transaction to be dangerous. -- **Honest by construction.** SIGN is the *weakest* claim in the system ("nothing here is recognized as dangerous"), never "this is safe." Malformed, unknown, or unresolved structure fails closed into HOLD/REJECT — never silent approval. -- **Tested, reported as-is.** 803 tests / 42 files · 14-program clear-signing registry with **69/69** Anchor discriminators cross-verified against canonical on-chain IDLs · mutation testing (Stryker, 70.2% behavioral) + fuzz (44,288 single-byte mutations of an authority transfer → **0** ever flip to SIGN) · 500 benign mainnet txs → 18.4% SIGN / 81.6% HOLD / **0 false-REJECT**. Zero runtime dependencies. MIT. +- **Real on-chain attack evidence.** The actual transactions that drained Drift (~$285M, Apr 2026) decode to **HOLD** *before* signing — durable-nonce advance + Squads v4 execution. That's the exact authority-handoff shape balance-diff checks miss, because nothing needs to move at signing time for the transaction to be dangerous. +- **Honest by construction.** SIGN is the *weakest* claim in the system ("nothing here is recognized as dangerous"), never "this is safe." A banned-phrase contract is executed over every verdict. Malformed / unknown / unresolved structure fails closed into HOLD/REJECT. +- **Tested, reported as-is.** 803 tests / 42 files · registry discriminators **69/69** cross-verified against canonical on-chain IDLs · mutation testing (Stryker, 70.2% behavioral) + fuzz (44,288 single-byte mutations of an authority transfer → **0** ever flip to SIGN) · 500 benign mainnet txs → 18.4% SIGN / 81.6% HOLD / **0 false-REJECT** · dual-parser cross-validation (@solana/web3.js v1 + @solana/kit v2) · **zero runtime dependencies** · MIT. ## Scope (honest limits) -Pre-sign review, **not** on-chain enforcement. The 37/37 attack-replay and 100%-recall figures are over a curated, mostly-synthetic corpus — not a population sample. sign-safe complements simulation, wallet UX, human review, and multisig/policy systems. +Pre-sign review, **not** on-chain enforcement. The 37/37 attack-replay and 100%-recall figures are over a curated, mostly-synthetic corpus plus 2 real Drift transactions — not a population sample. sign-safe complements simulation, wallet UX, human review, and multisig/policy systems; it is the byte-level static layer *before* the signing function is allowed to run. + +## Evaluate it + +```bash +# one line, no clone: +npx sign-safe + +# or the full suite from the public repo: +git clone https://github.com/lrafasouza/sign-safe-skill +cd sign-safe-skill && npm ci && npm run verify:all && npm run demo:attack-pack +# → 803 passed · 80 fixtures PASS/0 FAIL · 37/37 attacks held · False SIGN: 0 +``` ## Links - 📦 npm: https://www.npmjs.com/package/sign-safe -- 📂 Repo (full docs, danger catalog, 3-minute evaluator quickstart): https://github.com/lrafasouza/sign-safe-skill +- 📂 Repo (full docs, danger catalog, precision report, 3-minute evaluator quickstart): https://github.com/lrafasouza/sign-safe-skill - 🔗 Kit integration PR: https://github.com/solanabr/solana-ai-kit/pull/34 -Full documentation is in the [`sign-safe-skill`](./sign-safe-skill) submodule's `README.md` and `SKILL.md`. +Full documentation lives in the [`sign-safe-skill`](./sign-safe-skill) submodule's `README.md`, `SKILL.md`, `SECURITY.md`, and `docs/`.