helium

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities are mostly aligned, and the CLI install source appears official. The main risk is that all Helium access and auth are mediated by Membrane, expanding trust and data flow to a third party, plus the skill enables live destructive actions and uses an unpinned CLI version.

Confidence: 86%Severity: 54%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:38 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhelium%2F@ff9610e7f71f25f8923de012f0a61ba986ee5117
Security Audit — socket — helium