mem-init
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The file-editing behavior matches the stated bootstrap purpose, but the skill persists automatic execution of an unverified external npm package through CLAUDE.md guidance and an optional startup hook. The main risk is supply-chain trust and recurring third-party code execution, not confirmed malware.
Confidence: 83%Severity: 74%
Audit Metadata