simplemem
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core capabilities fit its stated purpose, and install sources are mostly legitimate. The main concern is data-flow integrity and scope sensitivity: the hosted path asks users to hand an OpenRouter API key to SimpleMem’s cloud service, and the cross-session features can capture rich project context. Not clearly malicious, but medium risk due to credential sharing with a third-party service and remote storage of sensitive agent memory.
Confidence: 82%Severity: 58%
Audit Metadata