simplemem

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core capabilities fit its stated purpose, and install sources are mostly legitimate. The main concern is data-flow integrity and scope sensitivity: the hosted path asks users to hand an OpenRouter API key to SimpleMem’s cloud service, and the cross-session features can capture rich project context. Not clearly malicious, but medium risk due to credential sharing with a third-party service and remote storage of sensitive agent memory.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:15 AM
Package URL
pkg:socket/skills-sh/evolv3-ai%2Fvibe-skills%2Fsimplemem%2F@0067616d514670051be9b9802113db5be3fa4000
Security Audit — socket — simplemem