memoryvault

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill is internally coherent as a cloud memory service and uses direct same-domain HTTPS endpoints, not a suspicious installer. However, it asks the agent to read a local credential file and routinely send broad session knowledge to a third-party hosted service, with added messaging/sharing/public features and exposure to untrusted remote content. The main risk is over-collection and externalization of sensitive context, not confirmed malware.

Confidence: 83%Severity: 64%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:31 PM
Package URL
pkg:socket/skills-sh/cairn-agent%2Fmemoryvault-skill%2Fmemoryvault%2F@d0beb165173d4afff668ca83f946b4d59fc82fb2