supermemory-add

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill’s core action is to execute an unverified local script with Bash/Node permissions and no provenance, source link, or integrity checks. No direct credential theft or malicious data flow is shown, but the executable trust gap makes the skill high risk.

Confidence: 84%Severity: 70%
Audit Metadata
Analyzed At
Jul 28, 2026, 03:27 AM
Package URL
pkg:socket/skills-sh/supermemoryai%2Fcodex-supermemory%2Fsupermemory-add%2F@452eaed6f939a2cd773c5e4f210ba269859f45eaa6438b22fbf9f5050ac489a2
Security Audit — socket — supermemory-add