archive

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow is coherent for a local session-archiving skill, and the flagged command-injection findings are benign documentation examples. The main issue is trust: the skill requires an unverifiable local helix binary/plugin with broad control over archive writes, server startup, and transcript ingestion, so install/provenance risk is high even without clear malicious or exfiltrating behavior.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Sep 10, 2026, 05:21 PM
Package URL
pkg:socket/skills-sh/teamhelix-ai%2Fhelix%2Farchive%2F@682ac270e6db1770abe8c7a7ad355d22455ca5270b7c7bea94f13b68660ba8eb
Security Audit — socket — archive