dflow-kalshi-portfolio
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill follows security best practices by instructing the agent to ask the user for API keys directly rather than assuming insecure defaults or environment variables.
- [EXTERNAL_DOWNLOADS]: The skill references an external MCP server for documentation and API reference at
https://pond.dflow.net/mcp, which is an official resource of the DFlow protocol. - [COMMAND_EXECUTION]: The skill instructs the agent on how to use the
dflowCLI tool for position retrieval, providing a direct path for local wallet inspection. - [SAFE]: The skill's functionality is strictly read-only, which significantly reduces the risk associated with indirect prompt injection from external market data.
Audit Metadata