memoriesweave

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with its stated MemoriesWeave design purpose and does not include malware-like installers or obvious credential theft. However, it uses a Convex-hosted API domain instead of a clearly first-party API host, sends the Bearer token across multiple domains, and handles unusually sensitive personal data (photos, conversations, relationship context). This looks more like a high-trust private integration than overtly malicious behavior.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 17, 2026, 07:16 AM
Package URL
pkg:socket/skills-sh/hero988%2Fmemoriesweave-skill%2Fmemoriesweave%2F@f632e40c497564dbbf344700c283b37d4c4f5dbc