helixa
Audited by Socket on Sep 24, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS. The skill is largely coherent with its stated blockchain identity purpose and uses plausible official endpoints, but it enables financial/blockchain actions, sends wallet-derived auth to a remote API, and introduces a third-party x402 payment path. These are proportionate for the use case but still create meaningful security risk, especially if an AI agent is allowed to act autonomously with wallet credentials.
This fragment contains a command-line-to-Python code injection vulnerability because untrusted input is embedded directly in Python source. The code does not by itself establish malicious intent, but callers who can control the query may be able to execute Python code. Fix by passing the query as a separate argument or encoding it without source-code interpolation.