helium-mcp

Pass

Audited by Gen Agent Trust Hub on Apr 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires configuration of an external MCP server URL (https://heliumtrades.com/mcp) to provide its functionality. This configuration directs the agent to interact with a third-party service provider.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from external news articles and memes. * Ingestion points: Data enters the context through search_news, get_article_bias, and search_memes tools. * Boundary markers: None identified in the skill instructions. * Capability inventory: The tools provided are restricted to read-only data retrieval and analysis. * Sanitization: No explicit sanitization or filtering of the ingested content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 25, 2026, 06:17 AM