helium-mcp

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill provides tools that ingest data from untrusted external sources, creating a surface for indirect prompt injection attacks.\n
  • Ingestion points: The get_bias_from_url tool (SKILL.md) takes an arbitrary URL as input and fetches its content for analysis.\n
  • Boundary markers: The skill instructions lack delimiters or warnings to the agent to ignore instructions embedded within the fetched external content.\n
  • Capability inventory: The agent has the capability to perform network requests to the configured MCP server (https://heliumtrades.com/mcp) to retrieve processed data from these external URLs.\n
  • Sanitization: There is no evidence of content sanitization or filtering to prevent malicious payloads embedded in articles or URLs from influencing the agent's output.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 06:42 PM
Security Audit — agent-trust-hub — helium-mcp