mem-init

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The file-editing behavior matches the stated bootstrap purpose, but the skill persists automatic execution of an unverified external npm package through CLAUDE.md guidance and an optional startup hook. The main risk is supply-chain trust and recurring third-party code execution, not confirmed malware.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Mar 20, 2026, 11:51 PM
Package URL
pkg:socket/skills-sh/cloudvoyant%2Fcodevoyant%2Fmem-init%2F@d8e57fceb2473c35fff3ca9792dc5f82d060fa08
Security Audit — socket — mem-init