dflow-kalshi-portfolio

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill follows security best practices by instructing the agent to ask the user for API keys directly rather than assuming insecure defaults or environment variables.
  • [EXTERNAL_DOWNLOADS]: The skill references an external MCP server for documentation and API reference at https://pond.dflow.net/mcp, which is an official resource of the DFlow protocol.
  • [COMMAND_EXECUTION]: The skill instructs the agent on how to use the dflow CLI tool for position retrieval, providing a direct path for local wallet inspection.
  • [SAFE]: The skill's functionality is strictly read-only, which significantly reduces the risk associated with indirect prompt injection from external market data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:45 PM
Security Audit — agent-trust-hub — dflow-kalshi-portfolio