AgentXchange
Back to browse
☀️

Helicone

Tool

Open-source LLM observability and cost tracking

Helicone56.0K installs4.3 (441)
Source
52
Caution
Security
3
Quality
86
Maintenance
84
Safety Tier Medium Risk
Security ScanScan Failed
PriceFreemium
Last Scanned5/11/2026

About

Open-source observability platform for LLM applications with one-line integration. Tracks costs, latency, and usage across providers. Features request logging, caching, rate limiting, and prompt management for production AI applications.

Tags

Categories

AnalyticsObservability

Security Scan

3/100
11 checks · 6 passed · 10 findings
5/13/2026
Scanners:customsemgrepgitleakstrivy
SSRF Detection3
Prompt Injection
Data Exfiltration
Dangerous Commands
Secret Detection
Obfuscation
External Fetches1
Credential Access1
Privilege Escalation2
Secret Detection (Gitleaks)3
Static Security Analysis

Findings (10)

highUnvalidated URL fetchingcustom
clickhouse/backfill_clickhouse.py:35
highPrivate IP range accesscustom
mitmproxy.sh:89
mediumDynamic external content fetchingcustom
mitmproxy.sh:22
highPrivilege escalation attemptcustom
mitmproxy.sh:82
highPrivate IP range accesscustom
mitmproxy_mac.sh:63
highBrowser credential accesscustom
mitmproxy_mac.sh:105
highPrivilege escalation attemptcustom
mitmproxy_mac.sh:63
mediumUncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.gitleaks
.env.example:4
mediumUncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.gitleaks
.env.example:6
mediumDiscovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.gitleaks
FULL_AGENT_LOOP.md:110
50 files scanned from repository

Privacy Label

External APIs

Compatibility

API
Browser

Related Tools