helmor-debug-operate
Warn
Audited by Socket on Jul 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is mostly coherent with its stated debugging purpose, but it grants strong local runtime control through injected JS and low-level IPC helpers over a non-official Tauri MCP bridge that may expose port 9223 beyond localhost. No clear malware or credential-harvesting behavior is present, but the bridge trust and backend-control footprint make this a medium-risk debugging skill rather than benign low-risk documentation.
Confidence: 84%Severity: 58%
Audit Metadata