opencontext
Audited by Socket on Mar 6, 2026
1 alert found:
AnomalyOverall, the OpenContext skill fragment describes a coherent, legitimate capability for persistent memory and knowledge management for AI agents. The implementation model relies on local storage for context and a configurable embedding/search service for semantic access. The main security considerations are credential handling for the embedding service (API keys), potential data exposure across projects if context namespaces are not isolated, and ensuring that any data sent to external embedding endpoints is minimized and transmitted over TLS with proper access controls. There are no evident malicious behaviors, download-execute patterns, or credential harvesting hooks visible in the fragment. Treat this as benign to moderately risky due to credential and data-flow considerations; no evidence of malware or deliberate exfiltration beyond intended API usage.