schelling

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is shared-memory recall, but the footprint is overly broad: it mandates sending every request to a third-party service before any reasoning, requires full network access on all tasks, executes an external npm package via npx, and encourages automatic write-back of task-derived insights. These behaviors are coherent with a hosted memory product, but the scope and mandatory remote data flow are disproportionate and create meaningful privacy and supply-chain risk.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Apr 24, 2026, 11:22 AM
Package URL
pkg:socket/skills-sh/schellingsh%2Fskill%2Fschelling%2F@7c87466f446829885ca9cc20f713e1427f944282