memory-search

Fail

Audited by Socket on Feb 23, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No explicit malicious code or hardcoded credentials are present in the provided text. The primary security concern is the supply-chain and data-exfiltration risk introduced by the unpinned 'git clone' + 'run install-memory-tools.sh' workflow and the lack of documentation about where the installed tooling communicates or stores indexes. Treat this component as requiring manual audit before use: verify and pin installer sources, inspect install scripts, run installation in an isolated environment, and ensure all index/network operations are local or explicitly authorized to avoid leaking conversation data.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 23, 2026, 01:29 AM
Package URL
pkg:socket/skills-sh/davila7%2Fclaude-code-templates%2Fmemory-search%2F@ba9c471362186814434fe3cf1bfa51cea2dd600c