helium-mcp
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill provides tools that ingest data from untrusted external sources, creating a surface for indirect prompt injection attacks.\n
- Ingestion points: The
get_bias_from_urltool (SKILL.md) takes an arbitrary URL as input and fetches its content for analysis.\n - Boundary markers: The skill instructions lack delimiters or warnings to the agent to ignore instructions embedded within the fetched external content.\n
- Capability inventory: The agent has the capability to perform network requests to the configured MCP server (
https://heliumtrades.com/mcp) to retrieve processed data from these external URLs.\n - Sanitization: There is no evidence of content sanitization or filtering to prevent malicious payloads embedded in articles or URLs from influencing the agent's output.
Audit Metadata