helius-dflow
Fail
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill documentation includes an installation command that pipes a remote script directly into the shell (
curl -fsS https://cli.dflow.net | sh). Piped remote execution is a high-risk pattern that executes unverified code from an external source. - [COMMAND_EXECUTION]: The skill integrates with the DFlow Agent CLI to execute autonomous trades, allowing the agent to generate and execute shell commands. This represents a powerful capability surface that interacts directly with the local execution environment.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted data from the Solana blockchain (such as token metadata, transaction history, and wallet identities) via Helius DAS and Wallet API tools. This data informs agent reasoning and CLI arguments without explicit instructions for sanitization or boundary enforcement.
- Ingestion points: Data is ingested via
heliusAsset,heliusWallet, and other Helius DAS/Wallet tools described in the reference files. - Boundary markers: The instructions do not specify the use of delimiters or instruction-ignoring markers when handling blockchain-sourced strings.
- Capability inventory: The agent can execute transactions, spend funds, and run shell commands via the
dflowCLI. - Sanitization: The instructions lack requirements for escaping or validating fields like token symbols, names, or transaction memos before they are used in tool invocations.
- [PROMPT_INJECTION]: There is a discrepancy in the metadata where the author is claimed to be
Helius Labs, while the developer context identifies the author ashosseinmirzapur. This type of metadata poisoning could mislead users regarding the official status and safety of the skill. - [EXTERNAL_DOWNLOADS]: The skill utilizes
npx helius-mcp@latestto install the Helius MCP server. As Helius is a trusted provider, this installation method is documented neutrally as a standard operational dependency.
Recommendations
- CRITICAL: 8 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata