dflow-spot-trading

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and routes data to official DFlow infrastructure, so it is not overtly malicious. But it carries high overall risk because it enables autonomous cryptocurrency trading, includes a transitive MCP dependency, and references a curl|sh CLI installer. Classify as SUSPICIOUS/HIGH-RISK rather than malware.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Apr 23, 2026, 04:03 AM
Package URL
pkg:socket/skills-sh/DFlowProtocol%2Fdflow-skills%2Fdflow-spot-trading%2F@b7cf9b61dc3160dbc6b15213c26c298bbdb9d2a6
Security Audit — socket — dflow-spot-trading