mem9-setup

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose broadly matches its actions, but it autonomously installs a third-party Claude plugin from a marketplace, creating a transitive trust chain that exceeds a simple config helper. The Mem9 API call and settings update are proportionate, yet the plugin installation materially increases risk without provenance details.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Mar 21, 2026, 10:57 PM
Package URL
pkg:socket/skills-sh/mem9-ai%2Fmem9%2Fmem9-setup%2F@b4ba325ffa016934d048f43588f20d54800f15e7