helpmetest-troubleshoot

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s troubleshooting behavior is purpose-aligned and not overtly malicious, but it relies on a third-party HelpMeTest MCP/CLI whose surfaced installation path is a same-vendor `curl|bash` installer without clearly verifiable release artifacts. Because the external tool appears to use an API token and receives project/test context, the main concern is supply-chain and credential/data exposure rather than confirmed malware.

Confidence: 82%Severity: 82%
Audit Metadata
Analyzed At
Mar 21, 2026, 11:50 PM
Package URL
pkg:socket/skills-sh/help-me-test%2Fskills%2Fhelpmetest-troubleshoot%2F@a9f2b8db30a591ec3d240f406054bc3d3857f70f