opencode-memory

Warn

Audited by Socket on Aug 26, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated memory capabilities are broadly aligned with its purpose, and no credential harvesting or explicit exfiltration is shown in the visible text. However, it relies on external plugin functionality with unclear provenance, omits installation/source details, and claims cross-project sync without explaining where data goes, making the overall footprint insufficiently transparent for a benign classification.

Confidence: 82%Severity: 64%
AnomalyLOW
src/hooks/memory-snapshot.ts

No strong indicators of malware, backdoor, or exfiltration are present in this module. The main concerns are security/privacy risk due to persisting recent session message content to local disk (including assistant output, and possibly more if tool calls are enabled) and potential path/target manipulation risk if `session.workingDirectory` and/or `session.id` can be influenced by an attacker (filename is only partially sanitized). Overall, this appears to be a data-retention feature with moderate risk, not an overtly malicious supply-chain payload.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Aug 26, 2026, 04:37 AM
Package URL
pkg:socket/skills-sh/digi4care%2Fopencode-mastery%2Fopencode-memory%2F@86be823af0975af5817a577bbda622414297b88b2eed79d26b5128c099f18b48
Security Audit — socket — opencode-memory