agent-memory-mcp-v2
Warn
Audited by Socket on Aug 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is plausible, but the skill’s actual footprint depends on cloning, installing, compiling, and running a third-party GitHub project from a different publisher, with instructions that do not clearly match the upstream project’s visible official setup. That makes install trust weak and gives outside code access to an arbitrary local workspace, which is disproportionate for a review-packaging skill and raises medium-high supply-chain risk.
Confidence: 84%Severity: 79%
Audit Metadata