helpmetest-proxy
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities are largely aligned with its stated proxy-testing purpose and data flows go to the expected same-org service, not an unrelated intermediary. However, it depends on a HelpMeTest CLI distributed through an official but unpinned `curl|bash` installer without surfaced release verification, which creates significant supply-chain risk; combined with tunneling local app traffic through HelpMeTest infrastructure, this makes the skill medium-to-high risk but not clearly malicious.
Confidence: 84%Severity: 72%
Audit Metadata