helpmetest

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's QA purpose mostly matches its capabilities, and the HelpMeTest installer appears same-org and publicly verifiable rather than an unrelated payload. The main concerns are autonomous testing on live sites, mandatory execution of an external CLI updater, and high indirect prompt-injection exposure from untrusted web content and optional local instruction files. This looks more like a high-risk QA orchestrator than confirmed malware.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 9, 2026, 03:06 AM
Package URL
pkg:socket/skills-sh/help-me-test%2Fskills%2Fhelpmetest%2F@9ff94cdf62140b0bf9425ba5049cc964052de904