mempalace-cognition

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a memory skill, and no explicit credential theft or external exfiltration is shown. The main issue is trust: the skill mandates execution of opaque local components (`~/.gemini/MemPalace_Manager.py`, local model file, local llama-server binary) whose provenance and behavior are not verifiable from the skill, creating medium-to-high supply-chain risk even though the visible workflow is locally scoped.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
May 20, 2026, 12:21 PM
Package URL
pkg:socket/skills-sh/Sebfranklin%2Ffranklin-skills%2Fmempalace-cognition%2F@651553fe225bee22040ae19d5fd2ca66ee0e5f11
Security Audit — socket — mempalace-cognition