stream

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and behaviors are mostly coherent for a live session dashboard, and the scanner’s command-injection hits are documentation false positives. The main concern is trust in the required local `helix` binary: the skill routes all core actions through an only partially verifiable executable that can open browsers, manage servers, and hold long-lived background waits.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Sep 10, 2026, 05:21 PM
Package URL
pkg:socket/skills-sh/teamhelix-ai%2Fhelix%2Fstream%2F@e3bd38fcf4c27f189388fcb5bdba6d5a72a37f8b195622b3001bfef33f41d8da
Security Audit — socket — stream