memos-local
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's general purpose aligns with installing a local memory plugin, but its footprint is too aggressive: autonomous no-confirmation execution, remote script fallback, credential collection for external APIs, gateway restarts, and transitive skill installation. The main concern is install/execution trust and secret exposure to newly installed code rather than confirmed malware.
Confidence: 87%Severity: 84%
Audit Metadata