SVS is seeking independent security review. No completed third-party audit,
certification, public bug bounty, or insurance coverage is currently claimed.
This packet defines what reviewers can test publicly and what requires a scoped
private-source engagement.
Primary objective
Verify fail-closed action authorization and evidence.
Determine whether SVS rejects consequential Solana agent actions that are unauthenticated, replayed, stale, altered, outside policy, missing approval, or unsupported by matching execution and registry evidence.
Signed request and nonce replay checksExact serialized-transaction bindingPolicy and human-approval enforcementAction-record and receipt-registry verificationPortable proof and secret-boundary review
The downloadable JSON pins the full npm shasum, PyPI wheel SHA-256, Git commit, and registry hash. Later package versions or registry hashes are new review targets unless explicitly included.
Public track
Inspect without private access.
Review the npm and PyPI clients, the two-phase reference workflow, public registry and trust manifest, verifier guidance, and threat model.
Do not open a public issue, discussion, pull request, or social post. Email hello@svsprotocol.com with [security] in the subject, then arrange a secure exchange channel before sending secrets, exploit material, wallet data, or sensitive evidence.