helius-dflow
Fail
Audited by Snyk on Aug 2, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). Most URLs are official Helius/DFlow endpoints and generally low-risk, but https://cli.dflow.net is referenced in the docs as a curl | sh installer (remote shell install), which is a high-risk distribution vector and should be treated as suspicious until verified.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill tells users to run "curl -fsS https://cli.dflow.net | sh" (references/integration-patterns.md) which fetches and executes a remote script at runtime (installing the DFlow CLI) and is presented as a required setup step for the agent workflow, so it is a high-confidence runtime remote-code-execution dependency: https://cli.dflow.net
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly exposes and documents transaction submission and trading APIs (Helius Sender, DFlow order API, transferSol), autonomous trade execution (DFlow Agent CLI that "handles wallet management, transaction signing, and execution — agents go from prompt to trade in a single command"), and concrete instructions/rules for submitting trades (priority fees, skipPreflight, Jito tips). These are specific financial execution capabilities (sending transactions, swapping tokens, executing orders), not generic tooling, so this grants Direct Financial Execution Authority.
Issues (3)
E005
CRITICALSuspicious download URL detected in skill instructions.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata