helius

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in purpose alignment, but HIGH security risk in operation: the skill is coherent for Solana/Helius development yet grants an AI agent financial/on-chain actions and onboarding/billing workflows, plus unpinned npx-based tool installation. No direct evidence of malware or credential theft, but the autonomy and supply-chain footprint make it a high-risk vulnerable skill.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 24, 2026, 10:14 PM
Package URL
pkg:socket/skills-sh/helius-labs%2Fcore-ai%2Fhelius%2F@ff48d3def6caf7d7811c8c3170d84e496033eba9