helius-openapi-skill
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The stated purpose is coherent and the intended API destination is the official Helius host, but the skill’s real trust boundary is the external `uxc` CLI and linked skill. Because this unverifiable third-party executable is required and receives the Helius API key, the skill should be classified as suspicious/high-risk rather than benign.
Confidence: 76%Severity: 82%
Audit Metadata