archive
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the workflow is coherent for a local session-archiving skill, and the flagged command-injection findings are benign documentation examples. The main issue is trust: the skill requires an unverifiable local helix binary/plugin with broad control over archive writes, server startup, and transcript ingestion, so install/provenance risk is high even without clear malicious or exfiltrating behavior.
Confidence: 82%Severity: 72%
Audit Metadata