memos-local

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's general purpose aligns with installing a local memory plugin, but its footprint is too aggressive: autonomous no-confirmation execution, remote script fallback, credential collection for external APIs, gateway restarts, and transitive skill installation. The main concern is install/execution trust and secret exposure to newly installed code rather than confirmed malware.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Apr 1, 2026, 06:20 PM
Package URL
pkg:socket/skills-sh/MemTensor%2FMemOS%2Fmemos-local%2F@74dbe58d7cc9a7a86ff18b8e80f6e58188fa11f7