Official Helius AI tooling repository
- capability exposureinferred+35
- recent driftinferred+20
- tool safetyinferred+25
inferred
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 13m ago · see ecosystem CVEs →
- D · 72 → E · 80
- D · 69 → D · 72
no known CVEs for this server.
- highdangerous code
credential logged in 1 file(s) · suspicious bundled script in 1 file(s)
- highexfiltration comboheliusChain
single tool reads + sends: net, secrets
- highhidden prompt content
11 file(s) with hidden prompt content: helius-labs-core-ai-8ce8bf9/.agents/skills/helius-dflow/prompts/claude.system.md (hidden-directive), helius-labs-core-ai-8ce8bf9/.agents/ski…
analyzed commit 8ce8bf9 · analyzer v17 · 23h ago
skills & prompt files 47
- ⚠ hidden: prompt-file: hidden-directivehelius-labs-core-ai-8ce8bf9/.agents/skills/helius-dflow/prompts/claude.system.md:2
Claude API — use as a system prompt block - ⚠ hidden: prompt-file: skill-exfilhelius-labs-core-ai-8ce8bf9/.agents/skills/helius-dflow/prompts/full.md:2212
secret→sink: - ⚠ hidden: prompt-file: hidden-directivehelius-labs-core-ai-8ce8bf9/.agents/skills/helius-jupiter/prompts/claude.system.md:2
Claude API — use as a system prompt block - ⚠ hidden: prompt-file: skill-exfilhelius-labs-core-ai-8ce8bf9/.agents/skills/helius-jupiter/prompts/full.md:1202
secret→sink: - ⚠ hidden: prompt-file: hidden-directivehelius-labs-core-ai-8ce8bf9/.agents/skills/helius-okx/prompts/claude.system.md:2
Claude API — use as a system prompt block - ⚠ hidden: prompt-file: skill-exfilhelius-labs-core-ai-8ce8bf9/.agents/skills/helius-okx/prompts/full.md:307
secret→sink: - ⚠ hidden: prompt-file: hidden-directivehelius-labs-core-ai-8ce8bf9/.agents/skills/helius-phantom/prompts/claude.system.md:2
Claude API — use as a system prompt block - ⚠ hidden: prompt-file: skill-exfilhelius-labs-core-ai-8ce8bf9/.agents/skills/helius-phantom/prompts/full.md:749
secret→sink: if (subpath.startsWith('v0/') || subpath.startsWith('v1/')) { - ⚠ hidden: prompt-file: hidden-directivehelius-labs-core-ai-8ce8bf9/.agents/skills/helius/prompts/claude.system.md:2
Claude API — use as a system prompt block - ⚠ hidden: prompt-file: skill-exfilhelius-labs-core-ai-8ce8bf9/.agents/skills/helius/prompts/full.md:1487
secret→sink: - ⚠ hidden: prompt-file: hidden-directivehelius-labs-core-ai-8ce8bf9/.agents/skills/svm/prompts/claude.system.md:2
Claude API — use as a system prompt block
- skillhelius-labs-core-ai-8ce8bf9/.agents/skills/helius-dflow/SKILL.md
- prompt-filehelius-labs-core-ai-8ce8bf9/.agents/skills/helius-dflow/prompts/openai.developer.md
- skillhelius-labs-core-ai-8ce8bf9/.agents/skills/helius-jupiter/SKILL.md
- prompt-filehelius-labs-core-ai-8ce8bf9/.agents/skills/helius-jupiter/prompts/openai.developer.md
- skillhelius-labs-core-ai-8ce8bf9/.agents/skills/helius-okx/SKILL.md
- prompt-filehelius-labs-core-ai-8ce8bf9/.agents/skills/helius-okx/prompts/openai.developer.md
- skillhelius-labs-core-ai-8ce8bf9/.agents/skills/helius-phantom/SKILL.md
- prompt-filehelius-labs-core-ai-8ce8bf9/.agents/skills/helius-phantom/prompts/openai.developer.md
- skillhelius-labs-core-ai-8ce8bf9/.agents/skills/helius/SKILL.md
- prompt-filehelius-labs-core-ai-8ce8bf9/.agents/skills/helius/prompts/openai.developer.md
- skillhelius-labs-core-ai-8ce8bf9/.agents/skills/svm/SKILL.md
- prompt-filehelius-labs-core-ai-8ce8bf9/.agents/skills/svm/prompts/full.md
- prompt-filehelius-labs-core-ai-8ce8bf9/.agents/skills/svm/prompts/openai.developer.md
- agent-ruleshelius-labs-core-ai-8ce8bf9/AGENTS.md
- agent-ruleshelius-labs-core-ai-8ce8bf9/CLAUDE.md
- agent-ruleshelius-labs-core-ai-8ce8bf9/helius-cli/CLAUDE.md
- skillhelius-labs-core-ai-8ce8bf9/helius-cursor/skills/build/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-cursor/skills/dflow/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-cursor/skills/jupiter/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-cursor/skills/okx/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-cursor/skills/phantom/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-cursor/skills/svm/SKILL.md
- agent-ruleshelius-labs-core-ai-8ce8bf9/helius-mcp/CLAUDE.md
- skillhelius-labs-core-ai-8ce8bf9/helius-plugin/skills/build/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-plugin/skills/dflow/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-plugin/skills/jupiter/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-plugin/skills/okx/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-plugin/skills/phantom/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-plugin/skills/svm/SKILL.md
- prompt-filehelius-labs-core-ai-8ce8bf9/helius-skills/SYSTEM-PROMPTS.md
- skillhelius-labs-core-ai-8ce8bf9/helius-skills/helius-dflow/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-skills/helius-jupiter/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-skills/helius-okx/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-skills/helius-phantom/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-skills/helius/SKILL.md
- skillhelius-labs-core-ai-8ce8bf9/helius-skills/svm/SKILL.md
danger signals2
- suspicious bundled scriptsuspicious bundled scripthelius-labs-core-ai-8ce8bf9/helius-skills/helius-okx/install.sh:78
echo " curl -fsSL https://raw.githubusercontent.com/okx/onchainos-skills/main/install.sh | bash" - credential in logscredential in loghelius-labs-core-ai-8ce8bf9/helius-cli/src/commands/signup.ts:552
console.log(`API Key: ${chalk.cyan(apiKey)}`);
- recent drift+20 capability drift →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of helius-labs.