mem-find
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, and it does not request disproportionate credentials or route data to obvious exfiltration endpoints, but it relies on unpinned `npx` execution of a package whose official provenance was not verified from the available evidence. This is primarily a supply-chain trust concern rather than clear malicious behavior.
Confidence: 82%Severity: 56%
Audit Metadata