helpwise
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is purpose-aligned and uses an official npm-distributed CLI, so there is little evidence of malware or deceptive installation. However, it routes Helpwise authentication and API traffic through Membrane’s third-party platform rather than directly to Helpwise, creating moderate credential-forwarding and data-flow risk; combined with the ability to perform consequential support actions, this makes the skill moderately risky rather than benign.
Confidence: 86%Severity: 61%
Audit Metadata