forge-memory

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The forge-memory skill presents a coherent, self-contained diagnostic tool for a local vector memory index. Its described operations, architecture, and data flows are consistent with a tool designed to index and retrieve memory from Markdown sources, with local embeddings and an internal SQLite index. The primary security caveat is the potential implicit download of embedding model weights at first run (not stated in the text but common for sentence-transformers). If such downloads occur automatically, ensure they come from trusted sources and are verifiable. Overall, the footprint is benign and proportional to its stated diagnostic purpose, with low risk of credential exposure or external data exfiltration.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 07:19 PM
Package URL
pkg:socket/skills-sh/fwehrling%2Fforge%2Fforge-memory%2F@779226a02ff5a7f82f108eb6bcca4c7acf39c7eb