helicone-observability
Warn
Audited by Socket on Feb 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Benign. The fragment is an integration guide for using Helicone as a proxy to collect observability data for LLM calls. It emphasizes proper credential handling (environment-based keys), explicit per-request headers for segmentation, and server-side configuration to avoid leaking secrets. No evidence of download/execute chains, embedded secrets in code, or exfiltration mechanics. Security risk is low when used as documented, though care should be taken to ensure keys remain server-side and that custom headers are not exposed in client bundles.
Confidence: 75%Severity: 75%
Audit Metadata