helius-dflow
Warn
Audited by Socket on Aug 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is purpose-aligned and mostly uses official Helius/DFlow channels, so it does not look like credential theft or covert malware. Risk is elevated because it adds external MCP servers, references a same-org curl|sh CLI path, forwards API/wallet context to outside tooling, and enables autonomous real-world crypto trading with financial consequences.
Confidence: 87%Severity: 74%
Audit Metadata