helius-jupiter

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is mostly coherent and routes data to official Helius/Jupiter services, but it expands an AI agent into high-impact financial operations and asks the agent to install an additional MCP server via an unpinned `npx @latest` path. This looks like a legitimate DeFi builder skill with meaningful security and autonomy risk rather than confirmed malware.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
May 15, 2026, 02:49 AM
Package URL
pkg:socket/skills-sh/helius-labs%2Fcore-ai%2Fhelius-jupiter%2F@d7d51b264c2e03c9ed86947917d36d889a29d8b5