helius-dflow

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and mostly uses official Helius/DFlow channels, so it does not look like credential theft or covert malware. Risk is elevated because it adds external MCP servers, references a same-org curl|sh CLI path, forwards API/wallet context to outside tooling, and enables autonomous real-world crypto trading with financial consequences.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Aug 2, 2026, 03:58 PM
Package URL
pkg:socket/skills-sh/hosseinmirzapur%2Fopencode-skills%2Fhelius-dflow%2F@952d6bbb4c347319ce03061ba5e04ef6d5526eb252fa6550038eebb6ee3f53de
Security Audit — socket — helius-dflow