memory-ingest

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The code fragment describes a coherent, purpose-aligned memory ingestion workflow with benign security implications. It focuses on internal data structuring, provenance, and optional light web research. The primary risk is privacy-related (verbatim preservation of potentially sensitive input) rather than exposure to exfiltration or execution. No suspicious download, credential handling, or external control paths are evident. Recommendation: ensure access controls and data minimization/pseudonymization are applied during ingestion to mitigate privacy risks. If memory-research is enabled, ensure strict curation and sandboxed web queries to avoid leakage of sensitive input beyond the intended scope.

Confidence: 65%Severity: 50%
Audit Metadata
Analyzed At
Feb 28, 2026, 07:58 PM
Package URL
pkg:socket/skills-sh/basicmachines-co%2Fbasic-memory-skills%2Fmemory-ingest%2F@f549204538f0c5024eee06a165920151f7e493ab