swarm

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior is largely coherent with its stated orchestration purpose and its data flow stays local, but it materially depends on a bundled `helix` CLI that could not be publicly verified from the provided evidence. That makes this primarily a supply-chain trust problem rather than malware, command injection, or exfiltration.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Sep 10, 2026, 05:21 PM
Package URL
pkg:socket/skills-sh/teamhelix-ai%2Fhelix%2Fswarm%2F@8966a5b27843d006f9c66bcc12772b9f61ec3092e97011355800928631a39114
Security Audit — socket — swarm