agent-memory-mcp
Warn
Audited by Socket on Aug 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose matches a memory MCP workflow, but the skill’s real footprint depends on cloning and running a separate third-party repo outside the publisher’s own project. No clear credential harvesting or malicious exfiltration is shown, so this is not confirmed malware; the main issue is medium supply-chain and trust-chain risk from executing external code over local workspace data.
Confidence: 84%Severity: 58%
Audit Metadata