cognitive-memory

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The cognitive-memory skill presents a coherent and ambitious architecture for multi-store memory with audit trails and reflection. Its footprint is largely self-contained (local file-based stores, git/audit logging, and in-context memory graphs) and proportionate to its stated purpose. The main security considerations are around internal reflection data exposure, audit/log retention, and ensuring explicit user consent and access controls for sensitive internal monologue content. No evident credential harvesting or external data exfiltration patterns are described. The presence of local init scripts and filesystem-based stores is normal for a developer tooling context, but verify script provenance and restrict access to sensitive memory content. Overall, the skill is BENIGN with MEDIUM risk due to privacy-sensitive data flows and the potential for inadvertent exposure of internal monologue content.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:25 AM
Package URL
pkg:socket/skills-sh/kirkluokun%2Fawesome-a-stock-openclawskills%2Fcognitive-memory%2F@40d2f9030af5152f64cee29fb3bd273d18b77dac