memmy-memory
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose is coherent for a memory CLI, but it relies on an external binary fetched at install time from a non-registry archive host without clear checksum/signature verification, and it forwards bearer tokens to arbitrary endpoints via --url/raw mode. That combination creates significant supply-chain and credential-routing risk even though the documented functionality matches the stated purpose.
Confidence: 90%Severity: 83%
Audit Metadata