agent-memory-mcp
Warn
Audited by Socket on Aug 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The stated purpose and capabilities are internally consistent for a memory MCP, and the instructions emphasize user approval and code review. However, it still installs and executes community GitHub code with npm dependencies outside an official registry package, and the server gets broad workspace access. Risk is mainly supply-chain and execution trust, not confirmed malicious intent.
Confidence: 80%Severity: 68%
Audit Metadata