memory-map

Fail

Audited by Snyk on Jun 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.90). This is a personal GitHub repo that instructs you to run local Python scripts and register global hooks that execute on every prompt (including optional external summarization using your OpenAI key), so executing unvetted code from an unknown account and giving it broad, persistent execution/access poses a high risk of data exfiltration or malicious behavior.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The skill contains explicit, high-risk data-exfiltration and remote-execution patterns: an opt‑in external summarization flow that sends conversation, file contents and environment details to an external LLM, lifecycle hooks that execute a local script on every user message (a frequent execution/exfiltration vector), and project/global MCP registration semantics that can be abused as a supply‑chain/backdoor to run arbitrary code across projects or machines.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 15, 2026, 04:09 PM
Issues
2
Security Audit — snyk — memory-map