dflow

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-consistent for Solana trading, but it enables autonomous financial actions and expands trust to external MCP/CLI components. The main concern is not hidden exfiltration; it is high-impact real-world trading authority combined with third-party tool installation and credentialed wallet workflows.

Confidence: 89%Severity: 79%
Audit Metadata
Analyzed At
Apr 19, 2026, 07:11 PM
Package URL
pkg:socket/skills-sh/helius-labs%2Fcore-ai%2Fdflow%2F@f39db0fb7be8fbbe17134d40e79daa26814238ee