helixa

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and mostly uses expected endpoints/tools for an onchain identity service, so it does not look fundamentally deceptive. However, it enables wallet-based auth, contract transactions, and micropayments with real financial consequences, and it processes untrusted user-generated API content that could carry prompt injection. Overall this is a coherent but medium-high risk skill for AI agents, driven more by autonomy and credential handling than by overt malware signals.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Apr 1, 2026, 02:43 AM
Package URL
pkg:socket/skills-sh/bankrbot%2Fmoltbot-skills%2Fhelixa%2F@66105048fd1d0c9a55c6637610336bdb98d6acd8