memos-local
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose mostly matches a local memory plugin installer, and the primary package/install path appears same-project and officially documented. However, the skill’s footprint is broader than a typical installer: it mandates no further approval, executes remote fallback scripts, edits persistent config, stores API keys, restarts the gateway, and relies on transitive skill installation. This looks more like high-trust automation than clear malware, but the autonomy and installer trust model make it medium-high risk.
Confidence: 87%Severity: 68%
Audit Metadata