mnemos

Warn

Audited by Socket on Jul 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose mostly matches its local checkpointing and transcript-ingestion behavior, and there is no clear network exfiltration. The main issue is install/execution trust: it relies on an undocumented mnemos CLI/binary with unverifiable provenance, while also processing sensitive local transcript data and injecting restored context automatically.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Jul 14, 2026, 04:18 PM
Package URL
pkg:socket/skills-sh/alinaqi%2Fmaggy%2Fmnemos%2F@5b981a7be82800c494342883cadd709f308215168fd8968cc2adb3d99e9a7307
Security Audit — socket — mnemos