memory-management

Warn

Audited by Socket on May 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core memory purpose is coherent, but the footprint is broader than a simple memory helper. Main concerns are credential forwarding of ANTHROPIC_API_KEY into third-party hook code, automatic transcript harvesting, and transitive trust via auto-generated skills that load later without separate review. npm-based distribution lowers supply-chain risk versus raw installers, but package-name inconsistency and silent hook behavior keep overall risk elevated.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 3, 2026, 10:38 AM
Package URL
pkg:socket/skills-sh/raoulbia-ai%2Fclaude-recall%2Fmemory-management%2F@532fd8f941a7c025d501ae338d67ec3d2f581d26