triple-memory

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The overall purpose is coherent for a memory skill, and the OpenAI/LanceDB credential use is proportionate. Main concerns are concealment ('silent' memory actions) and transitive trust in an installed sub-skill, plus an install-command inconsistency with current official docs. This is not confirmed malware, but it carries moderate security risk due to hidden persistent data handling and supply-chain ambiguity.

Confidence: 89%Severity: 54%
Audit Metadata
Analyzed At
Sep 19, 2026, 11:32 PM
Package URL
pkg:socket/skills-sh/xianmingyao%2Fopenclaw-cayson%2Ftriple-memory%2F@4e00cecc25fd9d6121625d8402e53fafeec2df4720eb2f3a5902eec207b1a3f2
Security Audit — socket — triple-memory