helpmetest-proxy

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities are largely aligned with its stated proxy-testing purpose and data flows go to the expected same-org service, not an unrelated intermediary. However, it depends on a HelpMeTest CLI distributed through an official but unpinned `curl|bash` installer without surfaced release verification, which creates significant supply-chain risk; combined with tunneling local app traffic through HelpMeTest infrastructure, this makes the skill medium-to-high risk but not clearly malicious.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 21, 2026, 11:50 PM
Package URL
pkg:socket/skills-sh/help-me-test%2Fskills%2Fhelpmetest-proxy%2F@f8570cff1769462391b64528d9c8bba82d6e1e7e