mymind
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s bookmark-search purpose is coherent, and the network destination looks like a first-party mymind host, but it depends on an unresolved local CLI and forwards highly sensitive browser session credentials to that binary. Because the binary’s provenance is not verifiable from the evidence and it receives raw auth material, this is a high-risk credential-forwarding pattern rather than a benign, well-scoped integration.
Confidence: 89%Severity: 84%
Audit Metadata