memmy-memory

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent for a memory CLI, but it relies on an external binary fetched at install time from a non-registry archive host without clear checksum/signature verification, and it forwards bearer tokens to arbitrary endpoints via --url/raw mode. That combination creates significant supply-chain and credential-routing risk even though the documented functionality matches the stated purpose.

Confidence: 90%Severity: 83%
Audit Metadata
Analyzed At
Aug 28, 2026, 06:29 AM
Package URL
pkg:socket/skills-sh/memtensor%2Fmemmy-agent%2Fmemmy-memory%2F@7d0d1a1c64b878a6392cc7be8c45f3ec54a1aadf0ef84d62d391453429ed3e12
Security Audit — socket — memmy-memory