swain-helm
Warn
Audited by Socket on May 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's stated bridge-management behavior is broadly coherent, but its real trust boundary is a local swain-helm binary that could not be independently verified. Because that opaque executable appears to receive 1Password/chat/opencode credentials and control persistent processes, the overall risk is high even without direct evidence of exfiltration.
Confidence: 85%Severity: 84%
Audit Metadata