byterover-cli-memory-layer
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core memory, query, local file access, and cloud sync capabilities fit the stated purpose, and install sources appear officially associated with ByteRover. However, the skill combines a pipe-to-shell installer, handling of multiple API keys, off-host sync of project knowledge, autonomous agent usage, and transitive package/connector installation, making the footprint broader and riskier than a simple documentation helper.
Confidence: 85%Severity: 66%
Audit Metadata