helius-dflow

Fail

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill documentation includes an installation command that pipes a remote script directly into the shell (curl -fsS https://cli.dflow.net | sh). Piped remote execution is a high-risk pattern that executes unverified code from an external source.
  • [COMMAND_EXECUTION]: The skill integrates with the DFlow Agent CLI to execute autonomous trades, allowing the agent to generate and execute shell commands. This represents a powerful capability surface that interacts directly with the local execution environment.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted data from the Solana blockchain (such as token metadata, transaction history, and wallet identities) via Helius DAS and Wallet API tools. This data informs agent reasoning and CLI arguments without explicit instructions for sanitization or boundary enforcement.
  • Ingestion points: Data is ingested via heliusAsset, heliusWallet, and other Helius DAS/Wallet tools described in the reference files.
  • Boundary markers: The instructions do not specify the use of delimiters or instruction-ignoring markers when handling blockchain-sourced strings.
  • Capability inventory: The agent can execute transactions, spend funds, and run shell commands via the dflow CLI.
  • Sanitization: The instructions lack requirements for escaping or validating fields like token symbols, names, or transaction memos before they are used in tool invocations.
  • [PROMPT_INJECTION]: There is a discrepancy in the metadata where the author is claimed to be Helius Labs, while the developer context identifies the author as hosseinmirzapur. This type of metadata poisoning could mislead users regarding the official status and safety of the skill.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx helius-mcp@latest to install the Helius MCP server. As Helius is a trusted provider, this installation method is documented neutrally as a standard operational dependency.
Recommendations
  • CRITICAL: 8 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — helius-dflow