mem-learn

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The functional scope matches a knowledge-capture skill, but the main risk is install/execution trust: it relies on an unpinned, externally fetched npm CLI whose publisher relationship and release provenance could not be verified from the provided evidence. No clear credential theft or explicit exfiltration is shown, so this is not confirmed malicious, but the runtime supply-chain risk is high enough to treat cautiously.

Confidence: 83%Severity: 76%
Audit Metadata
Analyzed At
Mar 20, 2026, 11:51 PM
Package URL
pkg:socket/skills-sh/cloudvoyant%2Fcodevoyant%2Fmem-learn%2F@043703d5772cf728e221ef0ab1fdf33eaefc694a
Security Audit — socket — mem-learn