Official Helius AI tooling repository
Drift inferred · capture-to-capture
- HIGH code analysis flagged hidden prompt content ×11 in helius-labs/core-ai
- HIGH code analysis flagged hidden prompt content ×11 in helius-labs/core-ai
- HIGH code analysis flagged hidden prompt content ×18 in helius-labs/core-ai
- HIGH code analysis flagged hidden prompt content ×18 in helius-labs/core-ai
transport stdio · http counts 10 tools · 0 res
· 0 prompts
permission surface via code analysis
tools
-
expandResult
expand summary-first results by resultId
-
heliusAccount
account setup, auth, plans, billing
-
heliusAsset
assets, NFTs, collections, token holders
-
heliusChain
raw chain state, token accounts, blocks, network status, stake reads, priority fees
-
heliusCompression
compressed account, proof, balance, and history queries
-
heliusKnowledge
docs, guides, pricing references, troubleshooting, source, blog, SIMDs
-
heliusStreaming
webhook CRUD and live subscription configuration
-
heliusTransaction
parsed transactions and wallet transaction history
-
heliusWallet
wallet balances, holdings, identity, wallet history
-
heliusWrite
SOL/token transfers and staking mutations
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed commit 7a59447 · analyzer v18 · 10h ago
skills & prompt files 47
- ⚠ hidden: prompt-file: hidden-directivehelius-labs-core-ai-7a59447/.agents/skills/helius-dflow/prompts/claude.system.md:2
Claude API — use as a system prompt block - ⚠ hidden: prompt-file: skill-exfilhelius-labs-core-ai-7a59447/.agents/skills/helius-dflow/prompts/full.md:2214
secret→sink: const response = await fetch(`https://mainnet.helius-rpc.com/?api-key=${API_KEY}`, { - ⚠ hidden: prompt-file: hidden-directivehelius-labs-core-ai-7a59447/.agents/skills/helius-jupiter/prompts/claude.system.md:2
Claude API — use as a system prompt block - ⚠ hidden: prompt-file: skill-exfilhelius-labs-core-ai-7a59447/.agents/skills/helius-jupiter/prompts/full.md:1204
secret→sink: const response = await fetch(`https://mainnet.helius-rpc.com/?api-key=${API_KEY}`, { - ⚠ hidden: prompt-file: hidden-directivehelius-labs-core-ai-7a59447/.agents/skills/helius-okx/prompts/claude.system.md:2
Claude API — use as a system prompt block - ⚠ hidden: prompt-file: skill-exfilhelius-labs-core-ai-7a59447/.agents/skills/helius-okx/prompts/full.md:309
secret→sink: `https://mainnet.helius-rpc.com/?api-key=${heliusApiKey}`, - ⚠ hidden: prompt-file: hidden-directivehelius-labs-core-ai-7a59447/.agents/skills/helius-phantom/prompts/claude.system.md:2
Claude API — use as a system prompt block - ⚠ hidden: prompt-file: skill-exfilhelius-labs-core-ai-7a59447/.agents/skills/helius-phantom/prompts/full.md:751
secret→sink: url = `https://api.helius.xyz/${subpath}?api-key=${HELIUS_API_KEY}`; - ⚠ hidden: prompt-file: hidden-directivehelius-labs-core-ai-7a59447/.agents/skills/helius/prompts/claude.system.md:2
Claude API — use as a system prompt block - ⚠ hidden: prompt-file: skill-exfilhelius-labs-core-ai-7a59447/.agents/skills/helius/prompts/full.md:1489
secret→sink: const response = await fetch(`https://mainnet.helius-rpc.com/?api-key=${API_KEY}`, { - ⚠ hidden: prompt-file: hidden-directivehelius-labs-core-ai-7a59447/.agents/skills/svm/prompts/claude.system.md:2
Claude API — use as a system prompt block
- skillhelius-labs-core-ai-7a59447/.agents/skills/helius-dflow/SKILL.md
- prompt-filehelius-labs-core-ai-7a59447/.agents/skills/helius-dflow/prompts/openai.developer.md
- skillhelius-labs-core-ai-7a59447/.agents/skills/helius-jupiter/SKILL.md
- prompt-filehelius-labs-core-ai-7a59447/.agents/skills/helius-jupiter/prompts/openai.developer.md
- skillhelius-labs-core-ai-7a59447/.agents/skills/helius-okx/SKILL.md
- prompt-filehelius-labs-core-ai-7a59447/.agents/skills/helius-okx/prompts/openai.developer.md
- skillhelius-labs-core-ai-7a59447/.agents/skills/helius-phantom/SKILL.md
- prompt-filehelius-labs-core-ai-7a59447/.agents/skills/helius-phantom/prompts/openai.developer.md
- skillhelius-labs-core-ai-7a59447/.agents/skills/helius/SKILL.md
- prompt-filehelius-labs-core-ai-7a59447/.agents/skills/helius/prompts/openai.developer.md
- skillhelius-labs-core-ai-7a59447/.agents/skills/svm/SKILL.md
- prompt-filehelius-labs-core-ai-7a59447/.agents/skills/svm/prompts/full.md
- prompt-filehelius-labs-core-ai-7a59447/.agents/skills/svm/prompts/openai.developer.md
- agent-ruleshelius-labs-core-ai-7a59447/AGENTS.md
- agent-ruleshelius-labs-core-ai-7a59447/CLAUDE.md
- agent-ruleshelius-labs-core-ai-7a59447/helius-cli/CLAUDE.md
- skillhelius-labs-core-ai-7a59447/helius-cursor/skills/build/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-cursor/skills/dflow/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-cursor/skills/jupiter/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-cursor/skills/okx/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-cursor/skills/phantom/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-cursor/skills/svm/SKILL.md
- agent-ruleshelius-labs-core-ai-7a59447/helius-mcp/CLAUDE.md
- skillhelius-labs-core-ai-7a59447/helius-plugin/skills/build/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-plugin/skills/dflow/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-plugin/skills/jupiter/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-plugin/skills/okx/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-plugin/skills/phantom/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-plugin/skills/svm/SKILL.md
- prompt-filehelius-labs-core-ai-7a59447/helius-skills/SYSTEM-PROMPTS.md
- skillhelius-labs-core-ai-7a59447/helius-skills/helius-dflow/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-skills/helius-jupiter/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-skills/helius-okx/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-skills/helius-phantom/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-skills/helius/SKILL.md
- skillhelius-labs-core-ai-7a59447/helius-skills/svm/SKILL.md
danger signals2
- suspicious bundled scriptsuspicious bundled scripthelius-labs-core-ai-7a59447/helius-skills/helius-okx/install.sh:78
echo " curl -fsSL https://raw.githubusercontent.com/okx/onchainos-skills/main/install.sh | bash" - credential in logscredential in loghelius-labs-core-ai-7a59447/helius-cli/src/commands/signup.ts:552
console.log(`API Key: ${chalk.cyan(apiKey)}`);
evidence-backed
findings quoted directly from the published source artifact — not inferred
filesystem 9
- fs helius-labs-core-ai-7a59447/helius-cli/src/commands/completions.ts :1
import fs from "fs"; - fs helius-labs-core-ai-7a59447/helius-cli/src/commands/keygen.ts :2
import fs from "fs"; - fs helius-labs-core-ai-7a59447/helius-cli/src/lib/config.ts :1
import fs from "fs"; - fs helius-labs-core-ai-7a59447/helius-cli/src/lib/feedback.ts :3
import fs from 'fs'; - fs helius-labs-core-ai-7a59447/helius-cli/src/lib/wallet.ts :1
import fs from "fs"; - fs helius-labs-core-ai-7a59447/helius-mcp/src/scripts/validate-catalog.ts :15
import fs from 'fs'; - fs helius-labs-core-ai-7a59447/helius-mcp/src/utils/config.ts :1
import fs from "fs"; - fs helius-labs-core-ai-7a59447/helius-mcp/src/utils/feedback.ts :3
import fs from 'fs'; - fs helius-labs-core-ai-7a59447/scripts/compile-skills.ts :13
import { readFileSync, writeFileSync, mkdirSync, cpSync, readdirSync, existsSync } from "fs";
shell / exec 4
- shell helius-labs-core-ai-7a59447/helius-cli/src/commands/update.ts :1
import { execSync } from "child_process"; - shell helius-labs-core-ai-7a59447/helius-cli/src/lib/browser.ts :1
import { spawn } from "node:child_process"; - shell helius-labs-core-ai-7a59447/helius-cli/src/lib/ows.ts :13
import { execFile } from "node:child_process"; - shell helius-labs-core-ai-7a59447/helius-mcp/src/utils/ows.ts :20
import { execFile } from 'node:child_process';
network 9
- net helius-labs-core-ai-7a59447/helius-cli/src/commands/simd.ts :35
const response = await fetch(SIMD_API_URL, { headers: githubHeaders() }); - net helius-labs-core-ai-7a59447/helius-cli/src/commands/update.ts :13
const res = await fetch(NPM_REGISTRY_URL); - net helius-labs-core-ai-7a59447/helius-cli/src/lib/feedback.ts :79
fetch(POSTHOG_ENDPOINT, { - net helius-labs-core-ai-7a59447/helius-cli/src/lib/helius.ts :132
const response = await fetch(url, { ...options, headers }); - net helius-labs-core-ai-7a59447/helius-cli/src/lib/loopback-server.ts :1
import { createServer, type Server } from "node:http"; - net helius-labs-core-ai-7a59447/helius-mcp/src/tools/solana-knowledge.ts :19
const response = await fetch(url, { - net helius-labs-core-ai-7a59447/helius-mcp/src/utils/docs.ts :102
const response = await fetch(url); - net helius-labs-core-ai-7a59447/helius-mcp/src/utils/feedback.ts :64
fetch(POSTHOG_ENDPOINT, { - net helius-labs-core-ai-7a59447/helius-mcp/src/utils/helius.ts :132
const response = await fetch(url, {
secrets 7
- secrets helius-labs-core-ai-7a59447/helius-cli/src/commands/simd.ts :18
if (process.env.GITHUB_TOKEN) { - secrets helius-labs-core-ai-7a59447/helius-cli/src/lib/helius.ts :38
if (process.env.HELIUS_API_KEY) return process.env.HELIUS_API_KEY; - secrets helius-labs-core-ai-7a59447/helius-mcp/src/index.ts :37
if (process.env.HELIUS_API_KEY) { - secrets helius-labs-core-ai-7a59447/helius-mcp/src/tools/config.ts :23
if (hasApiKey() && process.env.HELIUS_API_KEY) { - secrets helius-labs-core-ai-7a59447/helius-mcp/src/tools/laserstream.ts :150
` { apiKey: process.env.HELIUS_API_KEY, endpoint: "${endpoint}" },`, - secrets helius-labs-core-ai-7a59447/helius-mcp/src/tools/solana-knowledge.ts :50
if (process.env.GITHUB_TOKEN) { - secrets helius-labs-core-ai-7a59447/helius-mcp/src/utils/helius.ts :35
const apiKey = sessionApiKey || process.env.HELIUS_API_KEY || getSharedApiKey();