monitor-memory
Audited by Socket on Mar 17, 2026
2 alerts found:
Anomalyx2SUSPICIOUS. The skill’s purpose mostly matches a monitoring/orchestration role, and its documented data flows are local, but it has a high-risk always-on autonomous control loop with auto-repair via Bash and relies on unverified internal CLIs. This is not confirmed malware, but it is a high-trust operational skill that should only run in a tightly controlled environment with explicit user approval and verified local dependencies.
The code is not itself intentionally malicious, but it presents a significant local supply-chain risk: it executes arbitrary project-supplied scripts with the probe process privileges and reads their outputs into results. Malicious or tampered project scripts can exfiltrate data, modify the system, or perform other harmful actions. Recommend running these probes only against trusted projects or executing them inside a strong sandbox (container or restricted user) and adding integrity/allowlist checks for project scripts. Avoid relying solely on timeouts and captured output truncation as security controls.