dflow-spot-trading
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is purpose-aligned and routes data to official DFlow infrastructure, so it is not overtly malicious. But it carries high overall risk because it enables autonomous cryptocurrency trading, includes a transitive MCP dependency, and references a curl|sh CLI installer. Classify as SUSPICIOUS/HIGH-RISK rather than malware.
Confidence: 86%Severity: 74%
Audit Metadata