project-memory
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s local-only behavior and lack of external data routing argue against malware, but its footprint is broader than its stated project-memory purpose: it repeatedly scans global agent histories, configs, and unknown dotdirs to build handoff context. That makes it a medium-risk privacy and over-collection skill rather than a credential-stealing or clearly malicious one.
Confidence: 89%Severity: 56%
Audit Metadata