build

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core Helius/Solana capabilities align with the stated purpose, and most data flows appear to target official Helius services. Risk comes from unpinned npm-executed tooling, transitive MCP installation, and especially the skill's support for autonomous blockchain payments, upgrades, and transaction actions with real financial consequences.

Confidence: 84%Severity: 69%
Audit Metadata
Analyzed At
Apr 19, 2026, 07:16 PM
Package URL
pkg:socket/skills-sh/helius-labs%2Fcore-ai%2Fbuild%2F@5f4c14d751f806a8684e81de65c57ece371a76b0