Independent review packet

Test the trust claims. Do not infer them.

SVS is seeking independent security review. No completed third-party audit, certification, public bug bounty, or insurance coverage is currently claimed. This packet defines what reviewers can test publicly and what requires a scoped private-source engagement.

Primary objective

Verify fail-closed action authorization and evidence.

Determine whether SVS rejects consequential Solana agent actions that are unauthenticated, replayed, stale, altered, outside policy, missing approval, or unsupported by matching execution and registry evidence.

Signed request and nonce replay checks Exact serialized-transaction binding Policy and human-approval enforcement Action-record and receipt-registry verification Portable proof and secret-boundary review
Open machine-readable scope

Pinned baseline

Review one immutable public target.

0.6.0JavaScript SDK 0.2.0Python SDK a14e1d5Reference workflow f037bb60Devnet registry

The downloadable JSON pins the full npm shasum, PyPI wheel SHA-256, Git commit, and registry hash. Later package versions or registry hashes are new review targets unless explicitly included.

Public track

Inspect without private access.

Review the npm and PyPI clients, the two-phase reference workflow, public registry and trust manifest, verifier guidance, and threat model.

Open reference workflow Inspect registry

Private track

Review the operator core by agreement.

A contracted review can receive time-boxed private source access for request authentication, policy, approvals, transaction binding, receipt-registry integration, verification sets, signer lifecycle, and release integrity.

Production keys, API secrets, partner data, and unrelated generated archives are excluded.

Reproduce

Start with the public workflow.

git clone https://github.com/SVS-Protocol/svs-reference-workflow.git
cd svs-reference-workflow
git checkout e72654f29efc6b66962f191fa78dee87898f0a9a
npm install
npm test

Non-claims

Know what SVS does not prove.

No universal personhood claim No economic-safety guarantee No badge-only verification No devnet-to-mainnet equivalence No completed external audit claim

Private disclosure

Report suspected vulnerabilities privately.

Do not open a public issue, discussion, pull request, or social post. Email hello@svsprotocol.com with [security] in the subject, then arrange a secure exchange channel before sending secrets, exploit material, wallet data, or sensitive evidence.

Start private security contact