helicone-observability

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Benign. The fragment is an integration guide for using Helicone as a proxy to collect observability data for LLM calls. It emphasizes proper credential handling (environment-based keys), explicit per-request headers for segmentation, and server-side configuration to avoid leaking secrets. No evidence of download/execute chains, embedded secrets in code, or exfiltration mechanics. Security risk is low when used as documented, though care should be taken to ensure keys remain server-side and that custom headers are not exposed in client bundles.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 02:28 PM
Package URL
pkg:socket/skills-sh/phrazzld%2Fclaude-config%2Fhelicone-observability%2F@5798a4180ac910fbd775d724ebedb4a221774965