helpmetest-troubleshoot
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s troubleshooting behavior is purpose-aligned and not overtly malicious, but it relies on a third-party HelpMeTest MCP/CLI whose surfaced installation path is a same-vendor `curl|bash` installer without clearly verifiable release artifacts. Because the external tool appears to use an API token and receives project/test context, the main concern is supply-chain and credential/data exposure rather than confirmed malware.
Confidence: 82%Severity: 82%
Audit Metadata