memoriesweave

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated MemoriesWeave purpose, but its actual footprint is heavy: it processes full private conversations and photos, caches them locally, and routes authenticated API traffic to a non-brand `convex.site` host instead of a clearly official MemoriesWeave API domain. That endpoint mismatch and the volume of intimate data handled make the skill high-risk even without clear proof of malware.

Confidence: 83%Severity: 76%
Audit Metadata
Analyzed At
Mar 25, 2026, 06:23 AM
Package URL
pkg:socket/skills-sh/hero988%2Fmemoriesweave-skill%2Fmemoriesweave%2F@d889fa05205e612767d863d5de09ed93f765abf1