memory-management
Warn
Audited by Socket on May 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core memory purpose is coherent, but the footprint is broader than a simple memory helper. Main concerns are credential forwarding of ANTHROPIC_API_KEY into third-party hook code, automatic transcript harvesting, and transitive trust via auto-generated skills that load later without separate review. npm-based distribution lowers supply-chain risk versus raw installers, but package-name inconsistency and silent hook behavior keep overall risk elevated.
Confidence: 84%Severity: 74%
Audit Metadata