helius-openapi-skill

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The stated purpose is coherent and the intended API destination is the official Helius host, but the skill’s real trust boundary is the external `uxc` CLI and linked skill. Because this unverifiable third-party executable is required and receives the Helius API key, the skill should be classified as suspicious/high-risk rather than benign.

Confidence: 76%Severity: 82%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:16 AM
Package URL
pkg:socket/skills-sh/holon-run%2Fuxc%2Fhelius-openapi-skill%2F@9845757f327186646f2276824ef082644ca9194a
Security Audit — socket — helius-openapi-skill